Skip to content

Security: jpke/cursor-vibe-coding-template

SECURITY.md

📢 Responsible Disclosure

If you discover a security vulnerability in this project template, please:

  1. DO NOT create a public issue
  2. DO NOT disclose the vulnerability publicly
  3. DO email security details to: [Replace with your security email]
  4. DO give us reasonable time to respond and fix the issue

We will acknowledge receipt of your report within 48 hours and provide a timeline for resolution.

🔒 Security Best Practices for Users

When using this template for your own projects:

  1. Never commit API keys - Use environment variables and .env files
  2. Review all dependencies - Run security audits regularly
  3. Enable branch protection - Prevent direct commits to main
  4. Use pre-commit hooks - Catch issues before they're committed
  5. Keep dependencies updated - Monitor for security patches
  6. Configure repository secrets - Use GitHub's encrypted secrets for CI/CD

🛡️ Security Features

This template includes:

  • Gitleaks - Automatic credential detection
  • TruffleHog - Secret scanning
  • Pre-commit hooks - Prevent credential commits
  • GitHub Actions - Automated security scanning
  • Dependabot - Dependency security updates
  • CodeQL - Static analysis security scanning

There aren’t any published security advisories