Skip to content

Security: chf3198/devenv-ops

Security

.github/SECURITY.md

Security Policy

Supported Versions

Only the latest version on main is supported.

Reporting a Vulnerability

This is a private repository. If you discover a security issue:

  1. Do not open a public issue.
  2. Contact the maintainer directly via GitHub (@chf3198).
  3. Include: description, reproduction steps, and potential impact.

Scope

  • Secret exposure in git history, artifacts, logs, or docs
  • Hook scripts that could be exploited for privilege escalation
  • Dashboard endpoints that expose sensitive inventory data

Response

The maintainer will acknowledge within 48 hours and provide a fix timeline.

There aren’t any published security advisories