Skip to content

Security: ThanhNguyxnOrg/Locsight

Security

SECURITY.md

๐Ÿ”’ Security Policy

๐Ÿ›ก๏ธ Supported Versions

Version Supported
1.0.x โœ… Yes
< 1.0 โŒ No

๐Ÿ› Reporting a Vulnerability

If you discover a security vulnerability in Locsight, please report it responsibly:

  1. Do NOT open a public issue
  2. ๐Ÿ“ง Email: Create a private security advisory
  3. Include:
    • ๐Ÿ“‹ Description of the vulnerability
    • ๐Ÿ”„ Steps to reproduce
    • ๐Ÿ’ฅ Potential impact
    • ๐Ÿ’ก Suggested fix (if any)

โฑ๏ธ Response Time

Action Timeline
๐Ÿ“ฌ Acknowledgment Within 48 hours
๐Ÿ” Assessment Within 1 week
๐Ÿ”ง Fix release Within 2 weeks

๐Ÿ” Security Features

Locsight includes a built-in Secrets Scanner that detects:

  • ๐Ÿ”‘ AWS Access Keys
  • ๐Ÿ™ GitHub Personal Access Tokens
  • ๐Ÿ” Google API Keys
  • ๐Ÿ”’ Private Keys (RSA, DSA, EC)
  • ๐Ÿงฎ High-entropy strings (potential passwords/tokens)

โš ๏ธ All detected credentials are automatically masked before display. Only partial prefix/suffix is shown.

๐Ÿ“Œ Best Practices

  • ๐Ÿšซ Never commit secrets to source control
  • ๐Ÿ“„ Use .analyzer.json to exclude sensitive directories
  • ๐Ÿ” Add sensitive files to .gitignore
  • ๐Ÿ”„ Rotate any exposed credentials immediately

๐Ÿ›ก๏ธ Security is a shared responsibility. Thank you for helping keep Locsight safe.

There aren't any published security advisories