Skip to content

Security: filesdot/installer

Security

.github/SECURITY.md

dotfiles-banner

This project is a curated list of links, themes, and configuration resources.
As such, "security vulnerabilities" typically fall into one of these categories:

  • 🚩 Malicious or phishing links submitted to the list
  • πŸ”‘ Hardcoded secrets, API keys, or personal data in example configs
  • 🦠 Compromised upstream repositories or themes with supply-chain risks
  • πŸ•΅οΈ Doxxing or privacy violations in documentation/screenshots

πŸ“¬ Reporting a Vulnerability

If you discover a security-related concern, please do not open a public issue. Instead:

  1. Email us at: [email protected]
  2. Include:
    • URL/file location of the concern
    • Description of the risk
    • Steps to reproduce/verify (if applicable)
    • Your contact info (optional, for follow-up)

We acknowledge reports within 48 hours and aim to resolve critical issues within 7 days.

πŸ›‘οΈ What to Expect

  • βœ… Confidentiality: Your report will not be shared publicly without your consent
  • πŸ” Verification: We will validate the concern and assess impact
  • πŸ› οΈ Resolution: We'll remove/replace affected content, notify downstream users if needed, and update the list
  • πŸ™ Acknowledgment: With your permission, we'll credit you in our changelog/security advisories

πŸ“– Best Practices for Contributors

  • Never submit configs containing real tokens, passwords, or personal paths
  • Always verify upstream repo health before linking
  • Use placeholder paths in examples: ~/.config/tool/config.toml
  • If you maintain a linked project, keep dependencies updated and enable Dependabot/Renovate

πŸ“š References

There aren't any published security advisories