project-nomad/.github
Chris Sherwood d73fa6dcc9 docs: add SECURITY.md and tighten .gitignore for credential files
Adds a security policy so vulnerability reports are routed to the private
advisory form instead of public issues, and defines scope so the intentional
no-auth LAN design is not re-reported as a vulnerability.

Also adds a security contact link to the issue template chooser (blank issues
are disabled, so there was previously no route for a private report), and
extends .gitignore to cover .env variants, key/cert files, .npmrc/.netrc and
local copies of the deployed compose file. A local management compose with real
generated DB passwords was committed to a branch once before; secret scanning
push protection now covers that case too.

No tracked file is affected by the new ignore rules.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-10 08:51:43 -07:00
..
ISSUE_TEMPLATE docs: add SECURITY.md and tighten .gitignore for credential files 2026-08-10 08:51:43 -07:00
scripts docs: fix release action to include all commit info 2026-02-11 22:48:27 -08:00
workflows feat(creator-packs): gated per-creator video packs, offline via Kiwix (#1106) 2026-08-04 03:38:27 +00:00
dependabot.yaml ci: configure dependabot to target rc branch 2026-03-11 20:35:52 +00:00