Skip to content

Security: uinaf/dotfiles

SECURITY.md

Security

  • Report vulnerabilities privately to dev@uinaf.dev.
  • Include the affected file or setup step, reproduction, and impact.
  • Keep secret values, keys, and private machine details out of reports and public issues.
  • Use SOPS/age provisioning and recovery for credentials. Keep plaintext secrets out of shell startup, service definitions, and tracked or generated environment files.
  • Run security audits on the intended repository or host; treat raw output as sensitive.

There aren't any published security advisories