Skip to content

Security: timothywarner-org/prompt-pro

Security

SECURITY.md

Security Policy

Prompt Pro is a teaching repository, but we still treat security seriously so learners can model responsible engineering practices.

Supported Versions

Version Supported?
main ✅ Active maintenance for course deliveries
archived tags ⚠️ No fixes; update to main and rebase your workshop materials

Reporting a Vulnerability

  1. Email Tim Warner directly at tim@techtrainertim.com with the subject line Prompt Pro Security.
  2. Include:
    • Steps to reproduce (commands, environment, sample data)
    • Potential impact on learners (e.g., secret leakage, unsafe prompt, dependency risk)
    • Suggested remediation or temporary mitigation tips we can teach during class
  3. Please avoid opening public issues until Tim acknowledges receipt. I aim to respond within 2 business days and coordinate a fix or advisory shortly thereafter.

Disclosure Expectations

  • Do not test against production services you do not own; limit research to the repo and its sample assets.
  • Never share real participant data in reports—use sanitized samples or reference fictional personas.
  • If you find a vulnerability during a live session, notify the facilitator privately so we can keep the classroom experience constructive.

Thank you for helping keep this learning environment safe and exemplary for the community.

There aren’t any published security advisories