Skip to content

Security: happySNAG/World-Knowledge-Engine

Security

SECURITY.md

Security Policy

Scope

This repository is a public portfolio showcase for World. It contains documentation and illustrative SVG diagrams only. It does not contain production source code, runnable services, credentials, or personal datasets.

What never belongs in this repository

To keep the showcase safe and honest, the following must never be committed here:

  • API keys, tokens, passwords, or other credentials.
  • Private keys, certificates, or provisioning profiles.
  • Environment files (.env and variants) or configuration containing secrets.
  • Production databases, caches, logs, or archives.
  • Real personal data about any individual.
  • Absolute local filesystem paths, internal hostnames, or other machine-specific details.
  • Proprietary production source code.

The repository's .gitignore is configured to help keep these out, and the contents were secret-scanned before publication (see RELEASE_NOTES.md).

Reporting a concern

If you believe something sensitive has been committed here by mistake — a secret, personal data, or private source — or if you have another responsible-disclosure concern about this repository, please report it privately rather than opening a public issue with the details.

How to report:

  • Use GitHub's private vulnerability reporting for this repository if it is enabled: open the repository's Security tab and choose Report a vulnerability.
  • Otherwise, open a GitHub issue that says only that you have a security concern and asks for a private channel — without including the sensitive details — and the maintainer will follow up.

Please do not post secrets, personal data, or exploit details in a public issue.

Response

Reports about this showcase repository will be reviewed and, where a genuine exposure is confirmed, the offending content will be removed and the history addressed as appropriate. Because this repository intentionally contains no production systems, there is no production incident process associated with it.


Related: README · Contributing · License

There aren't any published security advisories