Skip to content

Security: andreinv-crypto/project-os-builder

SECURITY.md

Security policy

Project OS Builder must never receive credentials, private keys, .env files, raw customer data, form submissions, SQL backups, or private server logs.

Reporting a vulnerability

Do not open a public issue containing a vulnerability, secret, private path, or client evidence. Use the repository's private GitHub Security Advisory flow.

Include:

  • affected version;
  • minimal synthetic reproduction;
  • expected versus actual safety behavior;
  • whether a snapshot was promoted.

Supported release

The current design-partner release is v0.1.1.

There aren't any published security advisories