Skip to content

Security: keys-i/scripts

docs/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public issue for a security vulnerability.

Use GitHub's private vulnerability reporting so the problem can be discussed and fixed without exposing other users. If that form is unavailable, use a private contact method on the maintainer's GitHub profile.

Include:

  • the affected script and commit;
  • the security impact;
  • clear reproduction steps;
  • the affected operating systems or environments;
  • a suggested fix, if you have one.

Redact credentials, private data, hostnames, and other sensitive values. I will aim to acknowledge a complete report within seven days and will coordinate disclosure after a fix is available.

Supported Code

Only the latest version on main is supported. Vulnerabilities in third-party tools or libraries should also be reported to their maintainers.

Scripts in this repository may change files or system settings. Read them before running, use the least privilege required, and back up important data.

There aren't any published security advisories