- Block sensitive data being pushed to GitHub by git-secrets or its likes as a git pre-commit hook
- Audit for slipped secrets with dedicated tools
- Use environment variables for secrets in CI/CD (e.g. GitHub Secrets) and secret managers in production
The lastest version of treehfd is currently being supported with security updates.
If you believe you have found a security vulnerability, please let us know right away by contacting [email protected]. We will investigate all legitimate reports and do our best to quickly fix the problem.
If security vulnerabilities are detected, we will track them below, and mitigate the problems in further releases.
None.