Skip to content

Security: Cumulus-s/diffs

Security

SECURITY.md

Security

Do not commit secrets, tokens, private keys, local credentials, or private customer data.

Reporting

Report security issues through the private Cumulus security channel.

Do not open public issues for secrets or sensitive data.

Handling

  • Remove the sensitive data from the working tree.
  • Rotate any exposed credential.
  • Add a regression check when possible.
  • Document the fix in the changelog without repeating the secret.

There aren't any published security advisories