Don't post it publicly! Contact us privately:
- Open a private security advisory on GitHub
- DM the maintainers directly on GitHub
- What's broken
- How to reproduce it
- How bad is it
- Your fix idea (optional)
- Respond within 48 hours
- Fix it ASAP (critical stuff = days, not months)
- Credit you in the fix (unless you want to stay anonymous)
We're in MVP (v0.x.x). Security fixes will come fast once we hit v1.0.
Keep your deployments secure:
- Never commit credentials to git
- Use SSH keys instead of passwords
- Keep Terraform and Ansible updated
- Review infrastructure changes before applying
- Use environment variables for secrets
Follow these guidelines and your deployments will be secure.
We're in MVP mode. Security will improve as we grow. Found an issue? Let us know! 🔒