Reporting a vulnerability
- Please email [email protected] with details and steps to reproduce.
Secrets and environment variables
- Do not commit
.envfiles or real secrets..envfiles are globally ignored. - Use
.env.exampletemplates to document variables. - If a secret is leaked:
- Rotate the key immediately with the provider
- Purge history (see issue instructions: git-filter-repo or BFG)
- Verify GitHub secret scanning and push protection
Dependency security Trademarks and branding
- This project does not grant rights to use PuppyAgent trademarks, service marks, or logos
- Remove third-party brand assets unless explicitly licensed; prefer neutral icons
- Keep dependencies up to date; we use lockfiles and pinned versions where possible
- Enable GitHub Dependabot alerts and code scanning