Please do not report security vulnerabilities through public GitHub issues.
Instead, contact the maintainer privately with:
- A clear description of the vulnerability
- Steps to reproduce
- Affected endpoints or files
- Potential impact
- Any suggested mitigation
The maintainer will review the report and coordinate a fix before public disclosure.
ClassOps uses environment variables for runtime secrets. Do not commit:
.envfiles- Database passwords
- Mail app passwords
- API tokens
- Uploaded user files
- Logs containing personal data
If a real secret was committed in the past, rotate it before making the repository public.