-
Notifications
You must be signed in to change notification settings - Fork 0
SECURITY_RESPONSE
github-actions[bot] edited this page Jul 31, 2026
·
2 revisions
This runbook applies to every suspected vulnerability report, including one first posted publicly. Move a public report into a private GitHub Security Advisory immediately and do not continue discussing sensitive details in the public thread. The repository maintainer is the incident lead and owns release and disclosure coordination. Name a separate security reviewer whenever the risk policy requires independent review.
- Move the report into a private GitHub Security Advisory and restrict all evidence to people who need access.
- Remediate in the advisory's private fork or a separate access-controlled private repository. An unpushed local branch may be used for initial investigation if the workstation is appropriately protected.
- Never push a remediation branch or open a pull request in the public
repository until disclosure is coordinated. A branch in a public repository
is public even when it is named
privateor has no pull request.
- Contain the issue without reproducing sensitive content in logs, issues, command output, test fixtures, commits, or chat.
- Record affected data, provider and endpoint, version, reachable attack path, exploitability, severity, and affected release or capability gate.
- Revoke exposed credentials and consent grants, stop affected provider traffic, and preserve only sanitized evidence needed to reproduce and verify the issue.
- If repository history or a released artifact contains private data, coordinate removal with repository administration before rewriting history, and identify any people who require notification.
- Make the narrowest complete fix and add a regression test that uses only fictional data. Verify that legitimate offline, provider-consent, encrypted storage, RootsMagic, and GEDCOM behavior remains intact as applicable.
- Run the relevant targeted tests, then the canonical repository gates:
make test,make lint,make typecheck, andmake security. Record exact results. An interrupted security scan is incomplete. - Inspect commits, logs, generated reports, scan artifacts, SBOM changes, and the final diff for secrets or personal data before any public publication.
- If an existing workspace key is missing, restore the matching key from a secure backup; never generate a replacement key for that database.
- If a workspace key was disclosed, isolate the affected workspace and record the confidentiality impact. There is currently no supported public in-place rekey or migration command, so do not mark the key as rotated or improvise a destructive migration. A reviewed migration or recovery procedure remains a remediation blocker.
- Critical or High residual risk cannot be accepted for an affected privileged, MVP, high-risk-capability, or distribution gate. Close it with a verified fix or avoidance, or an evidence-backed false-positive disposition.
- Apply the owner, independent-review, evidence, rationale, compensating control, decision-date, and expiry requirements in the threat model to any permitted Medium or Low risk acceptance.
- Publish a concise advisory, affected-version statement, upgrade or mitigation guidance, and any required threat-model or control-matrix update only after the reporter and maintainer coordinate disclosure.
Response is complete only when every finding has a permitted disposition, no applicable release gate or expired exception remains open, verification evidence is recorded, and public guidance contains no sensitive data.
- Home
- CLI reference
- Interactive console guide
- Architecture ownership and dependency contracts
- Bounded file ingress
- Versioning and compatibility
- Continuous integration
- Release runbook
- Encrypted backup and recovery
- First-run storage diagnostics
- GEDCOM compatibility and release checks
- Built-in module authoring
- Privacy and consent
- Provider guide
- Local LLM benchmarks
- Local-first retrieval evaluation
- Wiki synchronization
- Wiki operations and recovery
- Security response checklist
- Electron and FastAPI desktop ADR
- Data-flow threat model and control matrix