Skip to content

Security: laranail/env-kit

SECURITY.md

Security Policy

Where this file is silent, the laranail security policy applies.

laranail/env-kit is a security-sensitive package: it reads and edits .env files and handles application secrets. Secret values are redacted from logs and exception messages by design. Please treat any vulnerability report with care and follow the private disclosure process below.

Supported Versions

Version Supported
0.1.x ✅

Reporting a Vulnerability

Please report security vulnerabilities privately. Do not open a public GitHub issue, pull request, or discussion for security problems.

Email security@simtabi.com with:

  • a description of the vulnerability and its impact;
  • the affected version(s);
  • steps to reproduce, or a proof of concept; and
  • any suggested remediation, if you have one.

What to expect

  • We aim to acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and work on a fix.
  • We will coordinate a disclosure timeline with you and credit you in the release notes unless you prefer to remain anonymous.

Thank you for helping keep the package and its users safe.

Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.

There aren't any published security advisories