.dotfiles

Security Policy

Scope

This repository is public and contains reusable dotfiles and setup scripts only. Do not store customer data, credentials, private keys, or internal identifiers here.

Reporting

If you find a security issue, do not open a public issue with sensitive details. Report privately to the maintainer and include:

Secret Handling Rules

Privacy Rules for Public Repos

Incident Response (If Something Leaks)

  1. Revoke/rotate exposed credentials immediately.
  2. Remove sensitive material from current files and Git history.
  3. Force-push cleaned history when required.
  4. Notify impacted stakeholders.
  5. Add/adjust detection rules to prevent recurrence.