Skip to content

Security: 8Dionysus/aoa-stats

Security

SECURITY.md

Security

Reporting

GitHub private vulnerability reporting is the canonical path for this repository.

If you discover a security issue, report it there first. Do not open a public issue or pull request for security-sensitive findings.

Report privately if you find

  • accidental secret leakage
  • credentials, tokens, or private keys
  • unsafe example data that exposes real infrastructure
  • private operational URLs, hostnames, or internal-only file paths
  • sensitive logs, receipt payloads, or config output that should not be public
  • a vulnerability that could materially affect users or maintainers

Do not post publicly

Public issues and pull requests are not appropriate for:

  • secret exposure
  • credential leaks
  • infrastructure-sensitive disclosures
  • unredacted logs, payloads, or config output
  • exploit details before maintainers have had time to assess the report

Contributor expectations

All contributed material must be:

  • sanitized
  • generalized where needed
  • free of secrets
  • safe for public reuse

There aren't any published security advisories