Skip to content

Security: vanessa49/nvidia-api-lifecycle-guard

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability or exposed credential. Contact the repository maintainers privately through the security advisory channel enabled for the repository, including a minimal reproduction and impact description. Do not include API keys, Authorization headers, user prompts, responses, or hidden reasoning content.

Supported boundary

This project is designed to keep credentials in the NVIDIA_API_KEY process environment and to report only redacted metadata. It does not perform live NVIDIA calls unless a user explicitly runs a probe with an already-present environment variable.

If a credential is committed, revoke or rotate it from a known-clean environment before opening a report.

There aren't any published security advisories