Only the master branch is supported. There are no versioned releases yet.
Do not open a public GitHub issue for security problems.
Report vulnerabilities privately:
- Use GitHub private vulnerability reporting if it is enabled on this repository.
- Otherwise email christopher.donohue@gmail.com with a description, impact, and steps to reproduce.
You should hear back within 7 days. Please do not disclose the issue publicly until a fix is released or you are told it is safe to do so.
Kuato is a password-gated dashboard. It does not store Sleeper credentials and cannot make picks. A shared SITE_PASSWORD signs an HMAC session cookie. Optional OPENAI_API_KEY / ANTHROPIC_API_KEY values are server-side only.
Keep those secrets in the host environment (or .env.local locally). Never commit .env* files other than .env.example.