Skip to content

Security: gadost/regitize

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest published version of Regitize.

Reporting a vulnerability

Use GitHub's private vulnerability reporting flow from the repository's Security tab. Do not open a public issue when a report includes an exploitable workflow, credential, token, private key, or sensitive repository content.

Include:

  • the affected Regitize version and skill;
  • a minimal reproduction using a disposable repository;
  • expected and actual behavior;
  • the potential impact;
  • suggested remediation, if known.

Do not include live credentials. Replace them with synthetic values that preserve only the relevant format.

Secret-scan findings

regitize-sensitive-scan is a local best-effort detector. A missed secret pattern is a valid security report about Regitize. A real credential discovered in another repository should be revoked with its provider and reported to that repository's owner, not disclosed in the Regitize issue tracker.

There aren't any published security advisories