Skip to content

Security: clownware/go-performance-starter

SECURITY.md

Security policy

Reporting a vulnerability

Use GitHub's private vulnerability reporting for this repository: Security → Report a vulnerability on github.com/clownware/go-performance-starter. Do not open a public issue or discuss the problem in a pull request until a fix is released. You will get an acknowledgement within a week, and credit in the CHANGELOG if you want it.

Scope

  • The template code in this repository: the Go application, migrations, workflows, Dockerfile, and the scripts/ tooling.
  • The public demo at go-performance-starter.fly.dev runs this code with anonymous guest identities and nightly resets. Its intended abuse surface and the mitigations in place are inventoried in ADR-031. Rate limits (429 with Retry-After), a request body cap, and CSRF checks are deliberate; hitting them is not a finding.
  • Row Level Security is the authorization model (ADR-004). A way to read or write another identity's rows through the application is the highest-priority class of report; the flashcards page carries a live isolation check you can run yourself (ADR-034).

Out of scope: vulnerabilities in Supabase, Fly.io, Cloudflare, or a dependency's upstream (report those to the vendor; a dependency advisory that govulncheck misses is still worth telling us about).

How the code is protected

The security patterns and threat model are ADR-014; the developer guide is auth-and-security.md. task ci runs govulncheck, go mod verify, a secret scanner (adr015-no-hardcoded-secrets), and the security-header tests on every push; vuln-scan.yml re-runs govulncheck on a schedule. Dependabot opens update PRs.

Secrets are never in the repository: 1Password injection locally, the container host's secret store in production (ADR-015). If you find one committed, report it privately as above.

There aren't any published security advisories