Skip to content

Security: opencoredev/s3-bench

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for vulnerabilities involving credential exposure, authentication bypass, arbitrary object access, or destructive storage behavior.

Report the issue privately through GitHub's security advisory feature for this repository. Include reproduction steps, affected versions or commits, and the potential impact. Do not include live cloud credentials or signed URLs.

Supported versions

Until the project publishes versioned releases, security fixes apply to the latest commit on the default branch.

Credential safety

S3 Bench reads cloud credentials from environment variables. .env, generated reports, local benchmark data, and dependency directories are ignored by Git, but contributors should still review changes and reports before sharing them publicly.

There aren't any published security advisories