Skip to content

Security: PlayaAI/camp-gifting-toolkit

Security

SECURITY.md

Security policy

Please do not open public issues for vulnerabilities or include real addresses, phone numbers, access tokens, signed links, provider credentials, or consent artifacts in reports.

Use GitHub’s private vulnerability reporting for this repository. Include affected routes, impact, reproduction steps using fictional data, and a suggested mitigation when possible.

Before production use, operators are responsible for configuring authentication, server-side authorization, token signing and expiry, webhook verification, upload limits, malware scanning, consent withdrawal, retention schedules, backups, and provider secrets.

There aren't any published security advisories