| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability, please do NOT open a public issue.
Instead:
-
Email: Create a private security advisory via GitHub
-
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
-
Response Time:
- Initial response: Within 48 hours
- Fix timeline: Depends on severity
This project follows these security practices:
- ✅ No API keys in code
- ✅ Environment variables for all credentials
- ✅
.gitignoreprotects sensitive files - ✅ Input sanitization on user queries
- ✅ HTTPS-only connections
- Free tier rate limits apply (Algolia, Gemini)
- Client-side environment variables are visible in browser
- No authentication system (public demo)
Thank you for helping keep Build Buddy secure!