Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: curiouscoder-cmd/ENV_Storage

Security

SECURITY.md

Security Policy

�� Our Commitment to Security

Security is paramount for ENV Storage Manager. We take the protection of your sensitive environment variables and API keys very seriously. This document outlines our security practices and how to report vulnerabilities.

🛡️ Security Features

Encryption

  • AES-256 Encryption: All stored secrets are encrypted using industry-standard AES-256 encryption
  • Key Derivation: Master passwords are processed using PBKDF2 with SHA-256
  • Salt Generation: Unique salts for each encryption operation
  • No Plain Text Storage: Secrets are never stored in plain text

Best Practices

  • Master Password: Never hardcoded or stored in plain text
  • Memory Protection: Sensitive data cleared from memory after use
  • Secure Deletion: Proper cleanup of temporary files
  • No Logging: Secrets are never logged or printed

📋 Supported Versions

We release patches for security vulnerabilities for the following versions:

VersionSupported
1.x.x
< 1.0

🐛 Reporting a Vulnerability

We appreciate responsible disclosure of security vulnerabilities. Please follow these guidelines:

Where to Report

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security issues via:

  1. GitHub Security Advisories (Preferred)

  2. Email (Alternative)

    • Send details to the repository maintainer
    • Use subject line: [SECURITY] Brief description

What to Include

Please provide:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and severity
  • Reproduction Steps: Detailed steps to reproduce the issue
  • Proof of Concept: Code or commands demonstrating the vulnerability
  • Suggested Fix: If you have ideas for fixing it
  • Environment: OS, Python version, package versions

Example Report

Subject: [SECURITY] Potential encryption key exposure in CLI output
Description:
When using the --debug flag, encryption keys may be exposed in console output.
Impact:
High - Could lead to unauthorized access to encrypted secrets
Steps to Reproduce:
1. Run: env-storage --debug export --project myapp
2. Observe console output contains encryption key
Environment:
- OS: macOS 14.0
- Python: 3.11.5
- ENV Storage: 1.0.0
Suggested Fix:
Sanitize debug output to exclude sensitive key material

⏱️ Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 1-7 days
    • High: 7-30 days
    • Medium: 30-90 days
    • Low: Next release cycle

🎯 Vulnerability Severity

We use the following severity levels:

Critical

  • Remote code execution
  • Authentication bypass
  • Encryption key exposure
  • Mass data breach potential

High

  • Local privilege escalation
  • Sensitive data exposure
  • Denial of service (persistent)

Medium

  • Information disclosure (limited)
  • Denial of service (temporary)
  • Security misconfiguration

Low

  • Minor information leaks
  • Best practice violations

🏆 Security Hall of Fame

We recognize security researchers who responsibly disclose vulnerabilities:

Be the first to help us improve security!

🔐 Security Best Practices for Users

For Users

  1. Strong Master Password

    • Use at least 16 characters
    • Include uppercase, lowercase, numbers, and symbols
    • Never reuse passwords from other services
    • Consider using a password manager
  2. Protect Your Vault

    • Never commit your vault file to version control
    • Regularly backup your encrypted vault
    • Store backups securely (encrypted cloud storage)
  3. Access Control

    • Limit file system permissions on vault files
    • Don't share your master password
    • Use separate vaults for different security contexts
  4. Keep Updated

    • Regularly update to the latest version
    • Review release notes for security patches
    • Enable notifications for security advisories
  5. Environment Security

    • Use the tool on trusted systems only
    • Be cautious of keyloggers and screen recording
    • Clear terminal history after sensitive operations

For Contributors

  1. Code Review

    • All code changes require review
    • Security-sensitive changes need extra scrutiny
    • Use static analysis tools
  2. Dependencies

    • Keep dependencies updated
    • Review dependency security advisories
    • Use only trusted packages
  3. Testing

    • Write security-focused tests
    • Test edge cases and error conditions
    • Never commit test data with real secrets
  4. Documentation

    • Document security implications
    • Update security docs with changes
    • Provide secure usage examples

🚫 Out of Scope

The following are generally considered out of scope:

  • Vulnerabilities in dependencies (report to the dependency maintainers)
  • Social engineering attacks
  • Physical access attacks
  • Denial of service via resource exhaustion (without amplification)
  • Issues requiring user to run malicious code
  • Theoretical vulnerabilities without proof of concept

📚 Security Resources

📜 Disclosure Policy

  • We follow a 90-day disclosure timeline
  • Security fixes are released as soon as possible
  • CVE IDs are requested for confirmed vulnerabilities
  • Public disclosure coordinated with reporter
  • Credit given to reporters (unless anonymity requested)

🔄 Security Updates

Subscribe to security updates:

  • Watch the repository for security advisories
  • Check the Security Advisories page
  • Follow release notes for security patches

📞 Contact

For security-related questions (non-vulnerabilities):


Thank you for helping keep ENV Storage Manager and our users safe! 🛡️

Last Updated: October 10, 2025

There aren't any published security advisories