Skip to content

Security: push-in/pam-http

Security

SECURITY.md

PAM API security policy

Do not report vulnerabilities in a public issue. Use GitHub private vulnerability reporting on the PAM repository.

Include the affected version, minimal reproduction, impact and any known mitigation. Do not include production credentials, personal data or active third-party targets.

Security support covers maintained releases listed by the root security policy. The PAM team will acknowledge a valid private report, coordinate remediation and publish an advisory after a fixed release is available.

Debug profilers must remain disabled in production. Signing keys, database credentials and bearer tokens must come from a secret manager and must never be included in logs, traces, diagnostics or issue reports.

There aren't any published security advisories