Skip to content

Security: volleyhq/volley-cli

Security

SECURITY.md

Security Policy

Supported Versions

We provide security updates for the following versions of Volley CLI:

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability, please follow these steps:

  1. Do NOT open a public GitHub issue
  2. Email us directly at security@volleyhooks.com
  3. Include the following information:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if you have one)

What to Expect

  • We will acknowledge receipt of your report within 48 hours
  • We will provide a detailed response within 7 days
  • We will keep you informed of the progress toward fixing the vulnerability
  • We will notify you when the vulnerability has been fixed

Disclosure Policy

  • We will credit you for the discovery (unless you prefer to remain anonymous)
  • We will coordinate with you on the disclosure timeline
  • We will not disclose the vulnerability publicly until a fix is available

Security Best Practices

When using Volley CLI:

  1. Keep it updated: Always use the latest version of Volley CLI
  2. Secure your credentials: Never commit your Volley API tokens or credentials
  3. Use HTTPS: Always use HTTPS endpoints when forwarding webhooks
  4. Validate webhooks: Verify webhook signatures when possible
  5. Review permissions: Only grant necessary permissions to your Volley account

Security Features

Volley CLI includes the following security features:

  • Secure credential storage (encrypted local storage)
  • HTTPS-only API communication
  • No credential logging
  • Token-based authentication

Additional Resources

Thank you for helping keep Volley CLI secure! 🔒

There aren’t any published security advisories