Skip to content

Security: PCWProps/scripts-make-it-easy

SECURITY.md

πŸ” Security Policy

πŸ“¦ Supported Versions

The following versions of our software and systems are currently supported for security updates:

Version Supported Notes
5.1.x βœ… βœ… Active development and security patches
5.0.x ❌ ❌ Deprecated; upgrade strongly recommended
4.0.x βœ… βœ… Maintenance-only support
< 4.0 ❌ ❌ No longer maintained

πŸ› οΈ Reporting a Vulnerability

Security is at the core of everything we build. If you believe you have discovered a security vulnerability, please report it responsibly using the steps below.

πŸ“© Submit a Report

Please send all vulnerability disclosures to our dedicated security email:
[email protected]
Alternatively, submit securely via https://pcwprops.com/disclosure (requires login).

Do not publicly disclose issues until we have responded with a resolution or timeline.


πŸ“… Response Timeline

You can expect a reply within 72 hours. We commit to the following response workflow:

  1. πŸ” Acknowledgement of the report
  2. πŸ§ͺ Verification and triage
  3. πŸ› οΈ Fix planning and internal patching
  4. πŸ“£ Disclosure timeline and CVE assignment (if applicable)

We believe in coordinated disclosure and will work with you to release any advisories responsibly.


🧰 Systems Covered

We actively monitor and maintain the security of all repositories and services related to:

  • Terraform infrastructure modules
  • Cloudflare firewall and DNS configurations
  • UniFi Identity SSO, VPN, and Zone Firewall policies
  • Home Assistant integrations and APIs
  • WordPress plugin code, templates, and custom themes
  • QuickBooks automation templates and app integrations
  • All codebases hosted within the PCWProps, PCWIntegrates, and dynamicmarching.com organizations

πŸ§ͺ Best Practices

All systems follow these security practices:

  • βœ… Secrets management via 1Password Connect Server
  • βœ… API tokens never stored in code or .env files
  • βœ… CI/CD audit trails with permission reviews
  • βœ… SSH key rotation and access revocation via GitHub SSO
  • βœ… Zero Trust policies applied via Cloudflare Gateway & Access

πŸ“Œ For developers: see our CONTRIBUTING.md for secure coding practices, or reach out to the DevSecOps lead via Slack or email.

Stay secure,
The PCW Security & DevOps Team

There aren’t any published security advisories