958 B
958 B
Security Policy
Reporting Vulnerabilities
Please report suspected vulnerabilities privately to the repository owner before public disclosure. Include:
- affected file or feature
- reproduction steps
- expected impact
- any relevant logs with secrets removed
Do not include real API keys, tokens, passwords, private keys, cookies, or other credentials in reports.
Secret Handling
Never commit .env, .env.local, credentials, private keys, provider tokens, or
local database files. Use .env.example for placeholders only.
If a secret is committed or pushed:
- Revoke or rotate the credential immediately.
- Remove it from the repository.
- Rewrite affected history.
- Force-push the cleaned branch only after rescanning.
Deployment Warning
This project is designed for local development. The Docker Compose sandbox
mounts /var/run/docker.sock; do not deploy that configuration publicly without
a hardened sandbox architecture.