Skip to content

Security: Carefree1987/workops

Security

SECURITY.md

Security Policy 🔐

Supported Versions

Only the latest version of the WorkOps repository is supported for security updates.

Version Supported
v1.0.x ✅ Yes
< v1.0 ❌ No

Reporting a Vulnerability

If you discover a security vulnerability (e.g., exposed tokens in logs, PII leaks), please report it responsibly:

  1. Do not open a public GitHub issue.
  2. Send an email to: sorgenfrei1987@gmail.com
  3. Include a detailed report of the breach and steps to reproduce.

Token Hygiene & PII

  • No Secrets: WorkOps implements a "Zero Token" policy for technical artifacts. All tokens are replaced by {{PLACEHOLDERS}} in templates and structural files.
  • Sensitive Data: Production logs are kept in private storage. Public ProofPacks contain synthetic or redacted evidence.

There aren’t any published security advisories