Use this section to tell people about which versions of your project are currently being supported with security updates.
| Version | Supported |
|---|---|
| 5.1.x | ✅ |
| 5.0.x | ❌ |
| 4.0.x | ✅ |
| < 4.0 | ❌ |
To keep API keys, database credentials, and other secrets out of the repository:
-
Never commit secrets. Files such as
middlewareNode/config/default.json,.env,*.local, and anyenvironment.secret.*file must never be tracked by git. These are already covered by.gitignore— do not remove or weaken those entries. -
Use environment variables for real credentials. Production values (Mongo URI, AWS access/secret keys, JWT signing key, Google OAuth client secret, Agora credentials, etc.) should be supplied via environment variables, mapped through
middlewareNode/config/custom-environment-variables.json, not hardcoded into tracked config files. -
Scan for sensitive data before every push. Run a quick check on what you're about to push:
git diff --cached | grep -iE "password\s*[:=]|api[_-]?key\s*[:=]|secret\s*[:=]|token\s*[:=]|aws_access_key_id|aws_secret|mongodb\+srv://|AKIA[0-9A-Z]{16}|GOCSPX-|BEGIN (RSA|PRIVATE) KEY"
For a more thorough check, run
detect-secrets scanorgit-secrets --scanover the changes before pushing. -
Automate it. Install
detect-secretsorgit-secretsas a pre-commit hook so this scan runs automatically on every commit, not just when remembered manually. -
If a secret is ever committed, treat it as compromised immediately: rotate/revoke the credential at its source (MongoDB, AWS, Google Cloud, etc.) regardless of whether history is rewritten, then remove it from git history with BFG Repo-Cleaner or
git filter-branch, and notify the team.
Before committing or pushing any changes, remove all references to Claude, Anthropic, or other AI coding assistants from the code and history:
-
Code comments and docstrings. Strip any comment that mentions "Claude", "Anthropic", "AI-generated", "Generated by AI", or similar. Replace with a neutral description of the change if a comment is still needed, or remove it entirely if it adds no value.
-
Variable, function, and file names. Rename anything referencing "claude", "anthropic", "ai", "assistant", etc. to neutral, descriptive names.
-
Commit messages. Do not include AI-assistant attribution (e.g.
Co-Authored-By: Claude ...) or mentions of AI tools in commit messages. -
Check before pushing. Run a quick scan of staged changes for these references:
git diff --cached | grep -iE "claude|anthropic|co-authored-by:.*claude"
Also review
git logfor any commit messages about to be pushed.
Use this section to tell people how to report a vulnerability.
Email: devin@ystemandchess.com
Tell them where to go, how often they can expect to get an update on a reported vulnerability, what to expect if the vulnerability is accepted or declined, etc.