Skip to content

Security: philband/dotenvsec

SECURITY.md

Security policy

Supported versions

Only the latest published release is supported while dotenvsec remains pre-production.

Reporting a vulnerability

Do not open a public issue for suspected vulnerabilities or disclose secret material. Use GitHub private vulnerability reporting for philband/dotenvsec. Include the affected version, reproduction steps using synthetic secrets, impact, and any suggested mitigation.

Automatic shell loading requires an independent security review and the real-hardware verification described in docs/threat-model.md before production use.

There aren't any published security advisories