Skip to content

Security: supaclank/web

SECURITY.md

Security

Please do not report security vulnerabilities in a public issue.

Use GitHub's private vulnerability reporting from the repository's Security page. Include a description, reproduction steps, and the impact you expect. The report is shared privately with the Supaclank maintainers so we can coordinate disclosure after a fix is available.

If GitHub's reporting form is unavailable, email security@supaclank.com.

The values prefixed with PUBLIC_, the Supabase publishable key, analytics configuration, and browser-facing form endpoints are intentionally public. Never submit private keys, service-role keys, access tokens, or deployment credentials to this repository.

There aren't any published security advisories