Skip to content

Security: taskade/docs

SECURITY.md

description How to report a security vulnerability in Taskade privately, plus security guidelines for docs contributors: never commit .env files, API keys, or tokens, use placeholder values, and clean git history if secrets leak.

Security Policy and Contributor Guidelines

⚠️ CRITICAL: This is a PUBLIC repository that powers docs.taskade.com. Never commit sensitive information!

Reporting a Security Vulnerability

Found a vulnerability in Taskade itself? Do not open a public issue or pull request. This repository is public, so anything filed here is visible to everyone, including anyone who would rather exploit the issue than see it fixed.

Report it privately instead:

  • Preferred: the Security tab of the affected repository, then Report a vulnerability.
  • Or email support@taskade.com with what you found, the steps to reproduce it, and the impact you believe it has.

We are a small team and do not guarantee a response time. We aim for 90-day coordinated disclosure when feasible, subject to investigation requirements, and on request we credit you by name once a fix ships. We do not run a bug bounty program. The full policy, including safe harbor terms, is published at taskade.com/security, and it is the one that applies.

The rest of this page is about not leaking secrets while contributing to these docs, which is a different problem from reporting a vulnerability in the product.

What NEVER to Commit

Environment Variables & Secrets

# ❌ NEVER commit these files:
.env
.env.local
.env.production
.env.development
*.key
*.pem
*credentials*
*secrets*
config/local.json
config/production.json

API Keys & Tokens

# ❌ Examples of what NOT to commit:
TASKADE_API_TOKEN=your_api_token_here
GITHUB_TOKEN=your_github_token_here
DATABASE_URL=postgres://user:password@host:5432/db
OPENAI_API_KEY=your_openai_key_here

Import Scripts & Temporary Data

# ❌ These are also excluded:
scripts/                    # Import/sync scripts
package.json               # Node dependencies for scripts
*-urls.txt                 # Temporary URL lists
help-center/_imported/     # Imported content (temporary)

Safe Practices

1. Use Template Files

Instead of .env, create .env.example.template:

# ✅ Safe template example:
# .env.example.template
TASKADE_API_TOKEN=your_api_token_placeholder
GITHUB_TOKEN=your_github_token_placeholder
OPENAI_API_KEY=your_openai_key_placeholder

2. Check Before Committing

Always run these commands before committing:

# Check what you're about to commit
git status
git diff --cached

# Look for sensitive patterns
git diff --cached | grep -i -E "(token|key|secret|password|credential)"

# Verify .gitignore is working
git ls-files | grep -E "\.(env|key|pem)$"

3. Use Git Hooks (Recommended)

Create .git/hooks/pre-commit:

#!/bin/bash
# Check for sensitive files
if git diff --cached --name-only | grep -E "\.(env|key|pem)$"; then
    echo "❌ ERROR: Attempting to commit sensitive files!"
    echo "Files found:"
    git diff --cached --name-only | grep -E "\.(env|key|pem)$"
    exit 1
fi

# Check for sensitive content
if git diff --cached | grep -i -E "(token|key|secret|password|credential)" | grep -v "placeholder"; then
    echo "❌ ERROR: Potential sensitive content detected!"
    echo "Content found:"
    git diff --cached | grep -i -E "(token|key|secret|password|credential)" | grep -v "placeholder"
    exit 1
fi

If You Accidentally Commit Secrets

Immediate Actions

  1. DO NOT PUSH if you haven't already
  2. Remove the sensitive file and commit:
git rm .env
git commit -m "Remove accidentally added .env file"
  1. If already pushed, immediately revoke/rotate the exposed credentials
  2. Contact the team lead immediately

Clean Git History

If secrets were pushed, use BFG Repo-Cleaner:

# Download BFG
wget https://repo1.maven.org/maven2/com/madgag/bfg/1.14.0/bfg-1.14.0.jar

# Remove sensitive files from history
java -jar bfg-1.14.0.jar --delete-files .env
java -jar bfg-1.14.0.jar --replace-text passwords.txt

# Force push (coordinate with team!)
git push --force

Pre-Commit Checklist

Before every commit, verify:

  • ✅ No .env files in staging area
  • ✅ No API keys/tokens in code
  • ✅ No credentials in configuration files
  • ✅ No temporary import scripts
  • ✅ No sensitive URLs or endpoints
  • ✅ All secrets use placeholder values like your_token_placeholder

Repository Structure

Public Content (✅ Safe to commit)

docs.taskade.com/
├── README.md              # Public documentation
├── api/                   # API documentation
├── features/              # Feature guides
├── genesis/               # Genesis documentation
├── automation/            # Automation guides
└── .gitbook/assets/       # Public images/assets

Private/Hidden Content (❌ Never commit)

Local Development Only:
├── .env                   # Environment variables
├── scripts/               # Import/sync scripts
├── help-center/_imported/ # Temporary imported content
├── package.json           # Script dependencies
└── *-urls.txt            # Temporary URL lists

Emergency Contacts

If you accidentally commit sensitive information:

  1. Immediate: Stop all commits/pushes
  2. Contact: Team lead or repository maintainer
  3. Action: Revoke/rotate exposed credentials immediately
  4. Follow-up: Clean git history if necessary

Additional Resources


Remember: This repository is PUBLIC and powers our documentation site. When in doubt, ask before committing!

There aren't any published security advisories