| description | How to report a security vulnerability in Taskade privately, plus security guidelines for docs contributors: never commit .env files, API keys, or tokens, use placeholder values, and clean git history if secrets leak. |
|---|
Found a vulnerability in Taskade itself? Do not open a public issue or pull request. This repository is public, so anything filed here is visible to everyone, including anyone who would rather exploit the issue than see it fixed.
Report it privately instead:
- Preferred: the Security tab of the affected repository, then Report a vulnerability.
- Or email support@taskade.com with what you found, the steps to reproduce it, and the impact you believe it has.
We are a small team and do not guarantee a response time. We aim for 90-day coordinated disclosure when feasible, subject to investigation requirements, and on request we credit you by name once a fix ships. We do not run a bug bounty program. The full policy, including safe harbor terms, is published at taskade.com/security, and it is the one that applies.
The rest of this page is about not leaking secrets while contributing to these docs, which is a different problem from reporting a vulnerability in the product.
# ❌ NEVER commit these files:
.env
.env.local
.env.production
.env.development
*.key
*.pem
*credentials*
*secrets*
config/local.json
config/production.json# ❌ Examples of what NOT to commit:
TASKADE_API_TOKEN=your_api_token_here
GITHUB_TOKEN=your_github_token_here
DATABASE_URL=postgres://user:password@host:5432/db
OPENAI_API_KEY=your_openai_key_here# ❌ These are also excluded:
scripts/ # Import/sync scripts
package.json # Node dependencies for scripts
*-urls.txt # Temporary URL lists
help-center/_imported/ # Imported content (temporary)Instead of .env, create .env.example.template:
# ✅ Safe template example:
# .env.example.template
TASKADE_API_TOKEN=your_api_token_placeholder
GITHUB_TOKEN=your_github_token_placeholder
OPENAI_API_KEY=your_openai_key_placeholderAlways run these commands before committing:
# Check what you're about to commit
git status
git diff --cached
# Look for sensitive patterns
git diff --cached | grep -i -E "(token|key|secret|password|credential)"
# Verify .gitignore is working
git ls-files | grep -E "\.(env|key|pem)$"Create .git/hooks/pre-commit:
#!/bin/bash
# Check for sensitive files
if git diff --cached --name-only | grep -E "\.(env|key|pem)$"; then
echo "❌ ERROR: Attempting to commit sensitive files!"
echo "Files found:"
git diff --cached --name-only | grep -E "\.(env|key|pem)$"
exit 1
fi
# Check for sensitive content
if git diff --cached | grep -i -E "(token|key|secret|password|credential)" | grep -v "placeholder"; then
echo "❌ ERROR: Potential sensitive content detected!"
echo "Content found:"
git diff --cached | grep -i -E "(token|key|secret|password|credential)" | grep -v "placeholder"
exit 1
fi- DO NOT PUSH if you haven't already
- Remove the sensitive file and commit:
git rm .env
git commit -m "Remove accidentally added .env file"- If already pushed, immediately revoke/rotate the exposed credentials
- Contact the team lead immediately
If secrets were pushed, use BFG Repo-Cleaner:
# Download BFG
wget https://repo1.maven.org/maven2/com/madgag/bfg/1.14.0/bfg-1.14.0.jar
# Remove sensitive files from history
java -jar bfg-1.14.0.jar --delete-files .env
java -jar bfg-1.14.0.jar --replace-text passwords.txt
# Force push (coordinate with team!)
git push --forceBefore every commit, verify:
- ✅ No
.envfiles in staging area - ✅ No API keys/tokens in code
- ✅ No credentials in configuration files
- ✅ No temporary import scripts
- ✅ No sensitive URLs or endpoints
- ✅ All secrets use placeholder values like
your_token_placeholder
docs.taskade.com/
├── README.md # Public documentation
├── api/ # API documentation
├── features/ # Feature guides
├── genesis/ # Genesis documentation
├── automation/ # Automation guides
└── .gitbook/assets/ # Public images/assets
Private/Hidden Content (❌ Never commit)
Local Development Only:
├── .env # Environment variables
├── scripts/ # Import/sync scripts
├── help-center/_imported/ # Temporary imported content
├── package.json # Script dependencies
└── *-urls.txt # Temporary URL lists
If you accidentally commit sensitive information:
- Immediate: Stop all commits/pushes
- Contact: Team lead or repository maintainer
- Action: Revoke/rotate exposed credentials immediately
- Follow-up: Clean git history if necessary
Remember: This repository is PUBLIC and powers our documentation site. When in doubt, ask before committing!