Security fixes are applied to the default branch (main). If you run a fork or
older snapshot, please rebase or cherry-pick fixes from main.
Do not open a public GitHub issue for security vulnerabilities.
Please report security issues privately:
- Prefer GitHub Security Advisories (private vulnerability reporting) when available on the repository.
- Otherwise email the maintainers using the contact method listed on the organization or repository profile.
Include:
- A clear description of the issue and impact
- Steps to reproduce (PoC)
- Affected component (web, api, collector, packages)
- Whether you plan to disclose publicly and on what timeline
We will acknowledge reports as soon as practical and coordinate a fix and disclosure timeline.
Good-faith security research against your own deployments or local instances of this software is welcome. Do not access data that is not yours, do not disrupt production SaaS systems you do not operate, and do not exfiltrate customer data.
- Never commit tokens, API keys, or real credentials.
- Use
.env/ secret managers for runtime secrets; see.env.example. - Product API keys are stored hashed and shown only once at create time.
The following require human review before merge:
- Auth/session and permission logic
- Billing and subscription behavior
- Database migrations with destructive potential
- CI/workflow permission scope changes
- Secret-loading and encryption logic
See docs/SECURITY.md and docs/AUTONOMY_POLICY.md for engineering policy.