| Version | Supported |
|---|---|
| 0.1.x | Yes |
Email the maintainers privately (do not open a public issue for exploitable bugs). Include:
- Affected version / commit
- Reproduction steps
- Impact (e.g. cross-user secret read, token forgery)
We aim to acknowledge within a few business days and coordinate a fix before any public disclosure.
- Secrets in source control — local mode keeps values in
.env(gitignored viajuice init); remote mode stores them in AWS Secrets Manager under/juice/users/<github-id>/…. - Cross-user access — authorization is owner-only by default; paths are
namespaced per GitHub user id.
listresults are filtered to the caller's prefix (IAM cannot scopeListSecretsby name). - Stolen long-lived credentials — user JWTs expire; machine tokens are scoped (project/env/actions), revocable, and cannot mint new tokens.
- Accidental value leaks in CLI UX — only
juice getprints a value (stdout);list/ confirmations / audit logs never include values.
- Anyone who can read your process environment can use injected secrets
(
juice run) or aJUICE_TOKENalready in the environment. - Anyone who can read
~/.juiceor the macOS Keychain entry can act as you against the API until the token expires or is revoked. - Local mode is only as safe as your disk and backups —
.envis a plain file (0600); Juice does not encrypt it at rest. - Host compromise / malicious dependencies in your app are out of scope.
- Account-wide
ListSecretson the API task role can enumerate secret names in the AWS account; the API must filter by caller prefix before returning keys. Do not weaken that filter.
- Never set a weak or hardcoded
JUICE_TOKEN_SECRET. The server refuses to start without a secret ≥32 characters. - Prefer HTTPS endpoints; the client rejects cleartext non-local
JUICE_API_URLunlessJUICE_ALLOW_INSECURE=1. - Repo
.envfiles must not be used for Juice control-plane config —JUICE_*keys there are ignored.