Skip to content

Security: lyc-aon/compress-store-agent-cli

Security

SECURITY.md

Security

Do not put secrets in GitHub issues, pull requests, screenshots, logs, or agent chats.

Secrets include:

  • ComPress store CLI API tokens;
  • passwords;
  • bearer tokens;
  • refresh cookies;
  • payment provider credentials;
  • SMTP credentials;
  • provider API keys;
  • raw credential files.

If a ComPress store CLI token is exposed:

  1. Revoke it in Admin > API Keys or with compress store token revoke.
  2. Create a new token.
  3. Re-run compress auth token-login locally.
  4. Remove the exposed token from any logs or files you control.

For security issues in the CLI or ComPress agent integration, use your normal ComPress support channel and do not include secret values in the report.

There aren't any published security advisories