Skip to content

Security: drengskapur/terraform-github-gitflow

Security

SECURITY.md

Security Policy

Supported Versions

We support the latest version of this Terraform module with security updates.

Version Supported
1.x.x βœ…
< 1.0 ❌

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability in this Terraform module, please report it responsibly:

πŸ”’ Private Disclosure

DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please:

  1. Email: Send details to [security@drengskapur.com] (if available)
  2. GitHub Security: Use GitHub's Security Advisories
  3. Direct Contact: Contact the maintainers directly

πŸ“‹ What to Include

When reporting a vulnerability, please include:

  • Description: Clear description of the vulnerability
  • Impact: Potential impact and attack scenarios
  • Reproduction: Steps to reproduce the issue
  • Affected Versions: Which versions are affected
  • Suggested Fix: If you have ideas for a fix

πŸ• Response Timeline

  • Initial Response: Within 48 hours
  • Assessment: Within 1 week
  • Fix Development: Depends on severity
  • Public Disclosure: After fix is available

πŸ›‘οΈ Security Best Practices

When using this module:

  1. Secrets Management: Never commit secrets to version control
  2. Least Privilege: Use minimal required permissions
  3. Regular Updates: Keep the module updated to latest version
  4. Review Changes: Review all changes before applying
  5. Audit Logs: Monitor GitHub audit logs for unexpected changes

πŸ” Security Features

This module includes several security features:

  • Advanced Security: GitHub Advanced Security integration
  • Secret Scanning: Automatic secret detection
  • Dependabot: Automated security updates
  • Signed Commits: Support for commit signing
  • Branch Protection: Comprehensive protection rules

πŸ“š Security Resources


Thank you for helping keep this project secure! πŸ”’

There aren't any published security advisories