Security fixes are applied to the latest published version of Regitize.
Use GitHub's private vulnerability reporting flow from the repository's Security tab. Do not open a public issue when a report includes an exploitable workflow, credential, token, private key, or sensitive repository content.
Include:
- the affected Regitize version and skill;
- a minimal reproduction using a disposable repository;
- expected and actual behavior;
- the potential impact;
- suggested remediation, if known.
Do not include live credentials. Replace them with synthetic values that preserve only the relevant format.
regitize-sensitive-scan is a local best-effort detector. A missed secret pattern is a valid security report about Regitize. A real credential discovered in another repository should be revoked with its provider and reported to that repository's owner, not disclosed in the Regitize issue tracker.