Skip to content

Security: Awakeniing/epo-ops-cli

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for security problems. Use GitHub's "Report a vulnerability" (Security → Advisories) on this repository, or contact the maintainers privately through the contact information on the repository page. You will get an acknowledgement within a week.

Please include: affected version/commit, reproduction steps or a proof of concept, and your assessment of impact.

What counts

Anything that could harm users of this tool, especially:

  • credential leakage or exfiltration (the tool must send the user's Consumer Key/Secret only to https://ops.epo.org/3.2/auth/accesstoken);
  • writes outside the documented locations (~/.epo/, user-specified output files);
  • injection through search results / API responses;
  • dependency or build-process compromises.

Design invariants (audit anchors)

These properties are intentional and protected:

  1. No telemetry. The tool collects nothing; the only outbound traffic is to ops.epo.org.
  2. Credentials stay local. Stored at ~/.epo/ops_config.json, never logged, never transmitted except to the EPO auth endpoint.
  3. No subprocess, no eval. The package never shells out and never dynamically evaluates strings.
  4. Single runtime dependency (requests).

A regression against any of these is a security bug — please report it.

There aren't any published security advisories