Skip to content

Security: CrownOpsEng/replaykit

Security

SECURITY.md

Security Policy

Replay Kit is an unstable alpha for rebuilding sanitized public Git history from local source history and exported issue/PR metadata. It is not a general secret-scanning service and it does not guarantee that arbitrary private data has been removed from a replayed repository.

Reporting a Vulnerability

Please use GitHub private vulnerability reporting if it is enabled on the repository. If that option is unavailable, open a minimal public issue that describes the affected component and ask for a private contact path without posting exploit details, secrets, or personal data.

Data Handling

  • Do not commit local manifests, replacement maps, source mirrors, replay reports, or state files.
  • Do not paste private repository names, internal paths, wallet addresses, account IDs, tokens, or API credentials into public issues or PRs.
  • Use the synthetic placeholders documented in docs/placeholder-policy.md when discussing sanitization behavior.

Supported Status

The current public release line is maintained on a best-effort basis while the project remains in alpha.

There aren't any published security advisories