If you discover a security vulnerability in playstealth-cli, please report it
responsibly:
- Email:
security@sin-clis.dev(PGP key available on request) - GitHub: open a private security advisory at https://github.com/SIN-CLIs/playstealth-cli/security/advisories/new
Do not open public issues for security concerns.
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
playstealth-cli never commits live secrets. The repository uses the following
controls:
.envand*.env.*are listed in.gitignoreand.dockerignore. Only.env.example(placeholder values) is tracked.- Recommended runtime injection: Infisical via
playstealth_actions.secret_manager.SecretManager(project ID + machine identity token are the only bootstrap variables that need to live in.env). - The CI workflow (
.github/workflows/ci.yml) runs asecurityjob that greps for hardcoded secrets and verifies.env.exampleonly contains placeholder values. - GitHub App private keys must be provided via the
GITHUB_APP_PRIVATE_KEYenvironment variable (PEM contents) or stored outside of the repository. PEM files in the working tree are ignored by git.
A NVIDIA AI API key was previously committed in .env at commit
bb966f8
(see issue #9). Mitigation steps that have been applied:
- The key has been rotated at the provider (NVIDIA NGC / build.nvidia.com).
.envhas been removed from the working tree and is ignored going forward..gitignoreand.dockerignorenow exclude all.env*variants except.env.example.- Secret-scanning is now part of CI (
securityjob).
If you maintain a fork that still includes the historical commit, run
git filter-repo (or BFG) to scrub the leaked value from your history and
force-push the cleaned branch.
Before deploying or contributing, make sure:
- No live secrets are committed to the repository or its forks.
-
playstealth_actions.secret_manager(or equivalent runtime injection) is used in production. - CI is green, including the
securityjob. - All operators have read
COMPLIANCE.mdand accept the responsible-use policy.