Skip to content

Security: OpenSciML/gitai

Security

SECURITY.md

Security

Do not include API keys, provider tokens, local .env files, or ~/.gitai/config.json contents in issues, pull requests, or logs.

If you discover a vulnerability, report it privately when GitHub private vulnerability reporting is available for this repository. Otherwise, contact the maintainer listed in pyproject.toml.

If a real provider key was committed or shared, rotate that key with the provider. Removing it from the working tree is not enough if it was already published in Git history.

There aren't any published security advisories