Do not open public GitHub issues for security vulnerabilities.
Security was a primary focus during the development of this project. However, if you discover a vulnerability or a potential risk, please report it directly to me at:
I will address any valid security concerns promptly.
- Strict Isolation: API keys (e.g., Groq, OpenAI) must never be committed to version control.
- Environment Variables: All secrets are loaded exclusively from a local
.envfile. - Git Protection: The
.gitignorefile is configured to strictly exclude.env,*.key, andsecrets/. - Key Rotation: In the event of an accidental commit, all exposed keys must be revoked and rotated immediately.
- No PII: This repository must not contain Personally Identifiable Information (PII).
- Synthetic Data: Use only anonymized or synthetic datasets for testing (e.g.,
data/RA_Application_Task.csv). - Output Sanitization: Review all generated artifacts (logs, CSVs, HTML) for sensitive data before committing.
- Vulnerability Scanning: We utilize GitHub Actions to scan dependencies for known CVEs.
- Minimal Footprint: Only essential, well-maintained packages are included in
requirements.txt.
Before submitting a Pull Request, verify the following:
- Secrets Check: No API keys or credentials are hardcoded.
- Git Status: The
.envfile is untracked. - Data Review: No real user data is present in outputs.
- Sanitization: Error messages and logs do not leak internal state or secrets.
- Input Validation: Sanitize all external inputs before processing.
- Fail Safe: Ensure the application fails securely without exposing stack traces to end-users.
- Audit Trails: Maintain observability (via OpenTelemetry) without logging sensitive payloads.