Skip to content

Security: jrgf/remotevars

Security

SECURITY.md

πŸ”’ Security Policy

🧭 Supported Versions

Security updates and patches are applied to the following versions:

Version Supported
0.x.x βœ… Current release
< 0.1.0 ❌ Not supported

Please make sure you are using the latest version of RemoteVars before reporting issues.


🐞 Reporting a Vulnerability

a If you discover a security vulnerability within RemoteVars:

  1. Do not open a public issue.

  2. Instead, please email the maintainers directly at:

    contact@josergarcia.dev
    
  3. Include:

    • A detailed description of the vulnerability
    • Steps to reproduce (if possible)
    • Any possible mitigations or suggested fixes

We’ll respond as soon as possible, usually within 48 hours.


🧱 Responsible Disclosure

We ask that all security researchers:

  • Respect user privacy and data integrity.
  • Allow reasonable time (usually 30 days) for us to release a patch before public disclosure.
  • Avoid exploitation or public demonstration without prior coordination.

πŸ” Additional Recommendations

For users of RemoteVars:

  • Avoid sharing .remotevars.json files with private tokens or credentials.
  • Prefer GitHub repositories with limited scopes or read-only access tokens.
  • If using HTTP providers, ensure you use HTTPS endpoints.
  • Regularly rotate credentials and access tokens.

There aren’t any published security advisories