Skip to content

Security: putdotio/rokit

Security

SECURITY.md

Security

If you believe you have found a security or privacy issue in this project, please report it privately.

Contact

Private reports are preferred for security and privacy issues.

If you are unsure whether something is sensitive, email first instead of opening a public issue.

Scope

Useful reports usually include issues involving:

  • token, secret, or credential exposure
  • unsafe handling of device passwords or signing keys
  • command injection through CLI arguments, env values, or device responses
  • publishing, release, or package integrity problems
  • private device, account, or media identifier exposure

Guidelines

  • test only against devices, accounts, environments, and data you control
  • keep testing non-destructive, low-volume, and service-safe
  • do not include device passwords, signing keys, account tokens, private content IDs, or local device identifiers in public issues, pull requests, examples, or logs

Supported Versions

Only the latest published version receives routine fixes.

Disclosure

Please allow a reasonable amount of time to investigate and fix the issue before sharing details publicly.

There aren't any published security advisories