This policy covers the code in this repository and the maintained deployment paths described in the operator docs.
If you discover a security issue, please report it privately:
- Do not open a public issue for an unpatched vulnerability.
- Use GitHub Security Advisories if they are enabled for this repository.
- Otherwise, contact the repository owner directly through a private channel.
- Never commit
.envor API keys. - Keep local runtime secrets in ignored files such as
.envor host-level secret paths. - Rotate credentials immediately if exposure is suspected.
Please allow reasonable time to validate and remediate the issue before any public disclosure.