This repository is maintained as an active personal project and portfolio case study.
Do not publish suspected credentials or vulnerabilities in a public GitHub issue. Contact the repository owner privately with:
- the affected file or component;
- steps to reproduce;
- the potential impact;
- any suggested remediation.
The following must never be committed:
- real
.envfiles; - API secrets or access keys;
- Telegram or webhook tokens;
- private keys or seed phrases;
- local SQLite databases;
- runtime logs and diagnostic exports;
- generated snapshot output;
- local backups or persistent state.
Only placeholder values belong in files ending with .example.