🔐 docs(security): update Security Policy to reflect TypeScript and Go stack
- Clarify that CheckCle is built with both TypeScript and Go - Add mention of Go-specific security practices (govulncheck, Go modules) - Improve clarity and consistency of security considerations
This commit is contained in:
+9
-10
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
## 📦 Project: [checkcle](https://github.com/operacle/checkcle)
|
## 📦 Project: [checkcle](https://github.com/operacle/checkcle)
|
||||||
|
|
||||||
**checkcle** is a lightweight, TypeScript-based built for uptime and server monitoring tools.
|
**checkcle** is a self-hosted uptime and server monitoring tool built with TypeScript and Go.
|
||||||
|
|
||||||
We care about the security and privacy of users running this project in production environments.
|
We care about the security and privacy of users running this project in production environments.
|
||||||
|
|
||||||
@@ -47,22 +47,21 @@ We support the latest stable release of `checkcle`. Security patches may also be
|
|||||||
|
|
||||||
## 🔍 Security Practices
|
## 🔍 Security Practices
|
||||||
|
|
||||||
This project adheres to the following practices to enhance security:
|
CheckCle follows these practices to improve overall security:
|
||||||
|
|
||||||
- 🔎 Regular vulnerability checks using `npm audit`
|
- 🔎 Regular vulnerability scanning (npm audit for JavaScript dependencies, govulncheck for Go modules)
|
||||||
- ⛓️ Dependency pinning via `package-lock.json`
|
- ⛓️ Dependency pinning (package-lock.json and Go modules)
|
||||||
- ✅ Type-safe code using `TypeScript`
|
- ✅ Type-safe code in TypeScript and memory-safe design in Go
|
||||||
- 🧪 Continuous testing and CI
|
- 🧪 Continuous testing and CI pipelines
|
||||||
- 🔐 No data is stored or transmitted unless explicitly configured by the user
|
- 🔐 No data is stored or transmitted unless explicitly configured by the user
|
||||||
- 🧑💻 All contributions are reviewed before being merged
|
- 🧑💻 All code contributions are reviewed before merging
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## ⚠️ Known Security Limitations
|
## ⚠️ Known Security Limitations
|
||||||
|
|
||||||
- `checkcle` makes outbound HTTPS requests to check certificate details — avoid running in untrusted or high-risk environments without proper network policies.
|
- Outbound HTTPS requests: CheckCle agents perform outbound HTTPS connections to send metric data to the backend server. Avoid deploying in untrusted or high-risk environments without appropriate network policies and monitoring.
|
||||||
- Output may contain certificate metadata (e.g., CN, SANs, expiry dates) — avoid exposing this to public logs unless sanitized.
|
- The data may be lost upon system restarts or crashes. Always ensure that backup (pb_data) and recovery mechanisms are in place in production environments.
|
||||||
- The data may be lost upon system restarts or crashes. Always ensure that backup and recovery mechanisms are in place in production environments.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user