Skip to content

Security: fralapo/clippyme

SECURITY.md

Security policy

Supported versions

ClippyMe has no releases. Only the current main branch receives fixes.

Reporting a vulnerability

Please report privately through GitHub: Report a vulnerability (Security tab → Advisories). Only the maintainers can see the report. Do not describe a vulnerability in a public issue, pull request or discussion.

Include the affected version (commit hash), the deployment setup (for example, bound to loopback, LAN with an API token, or behind a proxy), steps to reproduce, and the impact you observed.

Never post API keys, cookies, data/config.json, .env files, or logs that contain them — in reports, issues or pull requests.

Deployment scope

ClippyMe is built for a single trusted operator. By default both ports bind to 127.0.0.1, and every loopback or private-network client is trusted for settings and state-changing endpoints. Exposing it to a trusted LAN requires CLIPPYME_API_TOKEN; exposing it to the internet is not a supported configuration. Reports that depend on running it outside these conditions are still welcome, but will be treated as hardening. docs/deployment.md describes the model in full.

Handling secrets as a contributor

  • Keys belong in the dashboard Settings (stored in the git-ignored data/config.json) or a local .env, never in code, tests or docs.
  • Enable the secret-scan hook: git config core.hooksPath .githooks.
  • Tests build fake keys at runtime rather than containing key-shaped literals.

There aren't any published security advisories