Pudu programming language
Menu
Package

@chrismichaelps / pudu-lang-environment

Environment files for Pudu: load .env variables safely with layered files, discovery, expansion, typed reads, and secrets kept out of every message

0.1.0Apache-2.01

InstallClose

SECURITY.md

Markdown42 lines1.8 KB

GitHub ↗

Security policy

Reporting a vulnerability

Report a suspected vulnerability privately through GitHub's security advisory form, or by email to <chrisperezsantiago1@gmail.com> with SECURITY in the subject.

Please do not open a public issue for a vulnerability. Include the package version, the pudu version, the platform, and the smallest program that shows the problem. Never include a real secret in a report; replace every value with a placeholder.

You can expect an acknowledgement within seven days and a decision on whether the report is accepted within thirty.

What is in scope

The package reads environment files that hold secrets and hands their values to the program that asked. A report is in scope when a value escapes or a file is read that should not be:

  • A value read from an environment file appearing in a Problem, a description, a rendering with show, or any text the package produces.
  • An environment name that makes the layered files resolve outside the directory they were looked for in.
  • A variable expansion that reads a variable it was not asked for, or that does not terminate.
  • A file whose quoted value is never closed being loaded in part instead of refused.
  • A loaded value overriding a variable the process already holds when overwriting is off.
  • A variable handed to a child process that was not loaded or not asked for.

What is not in scope

  • A program that reveals a value it read on purpose, for example by printing Variables.text.
  • Secrets left in an environment file checked into version control; keep .env files out of it.
  • Vulnerabilities in the Pudu compiler or standard library; report those to pudu-lang.

Supported versions

VersionSupported
0.1.xYes