Skip to content

Security: NextStepGuru/dineros.cc

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security issue, do not open a public GitHub issue.

Please report it privately to: support@dineros.cc

Include:

  • a clear description of the issue;
  • reproduction steps or proof of concept;
  • affected files/endpoints;
  • impact assessment if known.

Response expectations

  • We will acknowledge receipt as soon as possible.
  • We will investigate and triage based on severity and exploitability.
  • We may ask for additional details to validate the report.

Disclosure policy

  • Please do not publicly disclose vulnerabilities until a fix is released or we explicitly approve coordinated disclosure.
  • We appreciate responsible disclosure and good-faith research.

Scope notes

  • Never include real credentials, API keys, tokens, or personal data in reports.
  • Redact secrets from screenshots and logs.
  • If you discover exposed secrets in commit history, tags, cached artifacts, or archived releases, report them through this process.

Supported versions

Security fixes are applied to the active main branch. Older commits and forks are not guaranteed to receive patches.

Ongoing hardening

This repository is actively moving toward stronger public-repo safeguards, including secret hygiene and key exposure review.

There aren't any published security advisories