镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Security: HowTo-Software/inventory

Security

.github/SECURITY.md

Security Policy

This is proprietary software (see LICENSE). Please handle security issues responsibly and privately.

Reporting a Vulnerability

  • Do not open a public issue for security problems.
  • Use GitHub's private vulnerability reporting (repository Security tab → Report a vulnerability), or contact the maintainers directly.
  • Include steps to reproduce, the affected component, and the potential impact.

Please allow a reasonable time for a fix before any disclosure.

Secrets & Credentials

  • Never commit .env, connection strings, JWT signing keys, API keys, or .pfx / .p12 private keys. These are ignored via .gitignore.
  • Runtime secrets are supplied through environment variables — see .env.example.
  • If a credential is ever exposed in a commit, rotate it immediately and scrub it from history before it is shared further.

There aren't any published security advisories