Skip to content

Security: gprzybycien/data-product-publish-readiness

Security

SECURITY.md

Security policy

Supported version

Version 1.0 is a prototype intended for local, read-only assessment of non-production or safely testable IBM Data Product Hub drafts.

Security properties

  • IBM REST operations are restricted to GET plus the read-only /v3/search POST.
  • IBM PUT, PATCH, DELETE, publication and artifact-creation operations are blocked in code.
  • IAM tokens are retained in memory and are never intentionally written to output.
  • GitHub issue creation requires the exact approval phrase APPROVE ISSUE.
  • The issue preview is regenerated from the report and compared before creation.

Secret handling

Do not commit .env, IBM API keys, bearer tokens, cookies, raw authorization headers or tenant-sensitive evidence. Prefer a dedicated, least-privilege IBM Cloud Service ID for persistent use. Rotate credentials after suspected exposure.

Reporting a vulnerability

Open a private GitHub security advisory. Do not include active credentials or tenant data in the report.

There aren't any published security advisories