Skip to content

Security: SC123667/info-push-platform

Security

SECURITY.md

Security Policy

Supported Versions

The current main branch receives security fixes.

Reporting a Vulnerability

Please open a private security advisory on GitHub when possible. Do not include live API keys, mail passwords, server credentials, cookies, or production database dumps in public issues.

Deployment Notes

  • Keep .env private.
  • Use a long random SECRET_KEY.
  • Change the default admin password before deployment.
  • Put public deployments behind HTTPS.
  • Rotate SMTP app passwords and API keys after any suspected exposure.
  • Do not commit generated databases, logs, APKs, app bundles, or backups.

There aren't any published security advisories