Skip to content

Security: pingops-io/pingops

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the default branch (main). If you run a fork or older snapshot, please rebase or cherry-pick fixes from main.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report security issues privately:

  1. Prefer GitHub Security Advisories (private vulnerability reporting) when available on the repository.
  2. Otherwise email the maintainers using the contact method listed on the organization or repository profile.

Include:

  • A clear description of the issue and impact
  • Steps to reproduce (PoC)
  • Affected component (web, api, collector, packages)
  • Whether you plan to disclose publicly and on what timeline

We will acknowledge reports as soon as practical and coordinate a fix and disclosure timeline.

Safe Harbor

Good-faith security research against your own deployments or local instances of this software is welcome. Do not access data that is not yours, do not disrupt production SaaS systems you do not operate, and do not exfiltrate customer data.

Secrets And Credentials

  • Never commit tokens, API keys, or real credentials.
  • Use .env / secret managers for runtime secrets; see .env.example.
  • Product API keys are stored hashed and shown only once at create time.

High-Risk Change Classes

The following require human review before merge:

  • Auth/session and permission logic
  • Billing and subscription behavior
  • Database migrations with destructive potential
  • CI/workflow permission scope changes
  • Secret-loading and encryption logic

See docs/SECURITY.md and docs/AUTONOMY_POLICY.md for engineering policy.

There aren't any published security advisories