Only the latest version of the WorkOps repository is supported for security updates.
| Version | Supported |
|---|---|
| v1.0.x | ✅ Yes |
| < v1.0 | ❌ No |
If you discover a security vulnerability (e.g., exposed tokens in logs, PII leaks), please report it responsibly:
- Do not open a public GitHub issue.
- Send an email to:
sorgenfrei1987@gmail.com - Include a detailed report of the breach and steps to reproduce.
- No Secrets: WorkOps implements a "Zero Token" policy for technical artifacts. All tokens are replaced by
{{PLACEHOLDERS}}in templates and structural files. - Sensitive Data: Production logs are kept in private storage. Public ProofPacks contain synthetic or redacted evidence.