Skip to content

Security: ismailperim/oncallmate

Security

SECURITY.md

Security Policy

Supported Versions

This project is pre-1.0 and receives best-effort security updates on main.

Reporting a Vulnerability

Please do not open public issues for vulnerabilities.

Report privately via repository security advisory or maintainer contact. Include:

  • Affected version/commit
  • Reproduction details
  • Impact assessment

We will acknowledge within 72 hours and work on a fix.

Security Notes for Operators

  • Treat Docker API access as privileged.
  • Prefer docker-socket-proxy with allowlisted endpoints.
  • Keep destructive actions gated by explicit approvals.
  • Rotate API keys and never commit .env.

There aren't any published security advisories