Skip to content

Security: OpenCnid/ralph-cli

Security

docs/SECURITY.md

Security

Data Handling

  • Never log secrets, tokens, or credentials
  • Validate and sanitize all external input
  • Use environment variables for secrets, never hardcode

Access Control

  • Principle of least privilege
  • Verify authorization at every entry point

Dependencies

  • Keep dependencies minimal and audited
  • Pin versions for reproducible builds

There aren’t any published security advisories