This repository is maintained as a portfolio and application codebase. Security fixes should target the current main branch unless a release branch is explicitly created.
Do not open public issues containing secrets, customer data, database dumps, credentials, or exploit details. Report privately to the repository owner with:
- affected area
- impact
- reproduction steps
- suggested mitigation if known
Never commit:
.envfiles- database dumps
- client documents
- generated reports
- AWS keys
- Mailgun keys
- ActiveCampaign tokens
- proxy credentials
- Cochrane credentials
- AI service keys
If a secret is exposed, rotate it immediately and remove it from active configuration. Do not rewrite history without explicit approval.