Initial WatchLink scaffold
Some checks failed
Build / build (push) Failing after 1m29s
Release Dry Run / release-dry-run (push) Successful in 1m24s
Template Compliance / compliance (push) Failing after 5s

This commit is contained in:
MrSphay
2026-05-15 03:11:41 +02:00
commit d3e84feedd
51 changed files with 2215 additions and 0 deletions

17
SECURITY.md Normal file
View File

@@ -0,0 +1,17 @@
# Security Policy
## Supported Version
WatchLink is pre-release. Security fixes apply to the current `main` branch.
## Reporting
Report vulnerabilities privately to the repository owner. Do not open public issues for secrets, authentication bypasses, or data exposure.
## Baseline Rules
- Do not commit `.env`, tokens, private keys, certificates, or database dumps.
- Change `NEXTAUTH_SECRET` before production use.
- Use a strong Postgres password in production.
- Store Gitea registry credentials in repository or organization secrets.
- Review `docs/security-review.md` before release work.