Skip to content

Security: Kushalrock/envsimplecli

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in EnvSimple CLI, please report it responsibly.

Do not open a public issue for security concerns.

How to Report

  1. Email: Send details to contact@envsimple.com
  2. GitHub: Open a private security advisory in the repository

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if available)

Response Time

We aim to acknowledge security reports within 48 hours and provide a fix timeline within 5 business days.

Disclosure Policy

We follow coordinated disclosure:

  1. You report the issue privately
  2. We confirm and develop a fix
  3. We release a patched version
  4. We publicly disclose the vulnerability with credit to the reporter

Security Best Practices

When using EnvSimple CLI:

  • Keep your CLI updated to the latest version
  • Use strong authentication
  • Never commit .env or .envsimple.local files
  • Review audit logs regularly
  • Rotate credentials periodically
  • Use environment-specific access controls

Contact

Security Team: contact@envsimple.com

There aren't any published security advisories