Skip to content

Security: YSTEM-LMS/react

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
5.1.x ✅
5.0.x ❌
4.0.x ✅
< 4.0 ❌

Preventing Credential Leaks

To keep API keys, database credentials, and other secrets out of the repository:

  • Never commit secrets. Files such as middlewareNode/config/default.json, .env, *.local, and any environment.secret.* file must never be tracked by git. These are already covered by .gitignore — do not remove or weaken those entries.

  • Use environment variables for real credentials. Production values (Mongo URI, AWS access/secret keys, JWT signing key, Google OAuth client secret, Agora credentials, etc.) should be supplied via environment variables, mapped through middlewareNode/config/custom-environment-variables.json, not hardcoded into tracked config files.

  • Scan for sensitive data before every push. Run a quick check on what you're about to push:

    git diff --cached | grep -iE "password\s*[:=]|api[_-]?key\s*[:=]|secret\s*[:=]|token\s*[:=]|aws_access_key_id|aws_secret|mongodb\+srv://|AKIA[0-9A-Z]{16}|GOCSPX-|BEGIN (RSA|PRIVATE) KEY"

    For a more thorough check, run detect-secrets scan or git-secrets --scan over the changes before pushing.

  • Automate it. Install detect-secrets or git-secrets as a pre-commit hook so this scan runs automatically on every commit, not just when remembered manually.

  • If a secret is ever committed, treat it as compromised immediately: rotate/revoke the credential at its source (MongoDB, AWS, Google Cloud, etc.) regardless of whether history is rewritten, then remove it from git history with BFG Repo-Cleaner or git filter-branch, and notify the team.

Removing AI Assistant References Before Committing

Before committing or pushing any changes, remove all references to Claude, Anthropic, or other AI coding assistants from the code and history:

  • Code comments and docstrings. Strip any comment that mentions "Claude", "Anthropic", "AI-generated", "Generated by AI", or similar. Replace with a neutral description of the change if a comment is still needed, or remove it entirely if it adds no value.

  • Variable, function, and file names. Rename anything referencing "claude", "anthropic", "ai", "assistant", etc. to neutral, descriptive names.

  • Commit messages. Do not include AI-assistant attribution (e.g. Co-Authored-By: Claude ...) or mentions of AI tools in commit messages.

  • Check before pushing. Run a quick scan of staged changes for these references:

    git diff --cached | grep -iE "claude|anthropic|co-authored-by:.*claude"

    Also review git log for any commit messages about to be pushed.

Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Email: devin@ystemandchess.com

Tell them where to go, how often they can expect to get an update on a reported vulnerability, what to expect if the vulnerability is accepted or declined, etc.

There aren't any published security advisories