If you discover a security vulnerability in any of the lab implementations or documentation, please report it responsibly.
- Do NOT open a public GitHub issue
- Contact me directly via LinkedIn: www.linkedin.com/in/orisraelche
- Include detailed information about the vulnerability
- Allow reasonable time for response and remediation
- Open a GitHub issue with the label
security-enhancement
- Suggest improvements to security practices
- Propose additional security controls
- β Production-ready security configurations
- β Principle of least privilege implementations
- β Compliance framework mappings
- β Cost optimization with security considerations
- β Real credentials or sensitive data
- β Overly permissive configurations
- β Security anti-patterns
- β Configurations that could create vulnerabilities
If you find security issues in the lab implementations:
- Assess Impact - Determine if it's a learning issue or actual vulnerability
- Report Privately - Use direct contact for serious issues
- Provide Details - Include steps to reproduce and potential impact
- Allow Response Time - Give reasonable time for remediation
When implementing these labs:
- Always use dedicated lab/development environments
- Never use production credentials
- Follow cleanup procedures to avoid unnecessary costs
- Review and understand all configurations before implementation
Thank you for helping keep this project secure and educational!