Skip to content

Security: Vibhav-Aggarwal/vahan-ops

Security

SECURITY.md

Security Policy

Scope

Vahan Ops handles personally identifiable vehicle and legal data on the user's own machine. The main risks are accidental disclosure (committing real data or credentials) and credential handling for the Vahan citizen account.

Reporting a vulnerability

Please do not open a public issue for security problems. Email the maintainer (see the GitHub profile of the repository owner) with details; you will get an acknowledgement within 7 days.

Handling secrets

  • All credentials go in .env (gitignored). .env.example documents the keys with placeholder values.
  • data/, config/vehicles.yaml, and captcha/ are gitignored by default.
  • Pre-commit runs detect-secrets and a regex check for Indian registration-number and 10-digit phone patterns in tracked files.

There aren't any published security advisories