Skip to content

Security: pxinnovative/px-secrets

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes

Reporting a Vulnerability

If you discover a security vulnerability in PX Secrets, please do not open a public issue.

Instead, report it responsibly:

  1. Email: github@pxinnovative.com
  2. Subject: [SECURITY] PX Secrets — <brief description>
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if you have one)

What to Expect

  • Acknowledgment within 48 hours
  • Assessment within 7 days
  • Fix or mitigation as soon as possible, depending on severity
  • Credit in the release notes (unless you prefer to remain anonymous)

Scope

This policy covers the PX Secrets application and its dependencies as distributed in this repository. It does not cover third-party tools (SOPS, AGE) — report those to their respective maintainers.

Privacy Note

PX Secrets is designed with privacy as a core principle. All encryption and decryption happens locally on your machine using SOPS + AGE. No data is ever sent to any server. If you believe this guarantee has been compromised, please report it immediately.

Thank You

We take security seriously and appreciate the community's help in keeping PX Secrets safe for everyone.

There aren't any published security advisories