go-masker reduces accidental exposure of sensitive values in logs,
diagnostics, and observability payloads. It is not a replacement for access
control, encryption, secret storage, or review of application-specific
policies and custom rules.
Report suspected vulnerabilities privately through GitHub Security Advisories. Do not report them in a public issue or pull request. Do not include real credentials, production personal data, or unredacted payloads. Synthetic reproductions and the smallest affected input are preferred.
Reports should include the affected operation, Go version, a minimal reproduction, and whether the issue can expose the original value after an error. Maintainers should acknowledge reports, assess severity, and publish a fix or mitigation before discussing details publicly.
- Treat custom
PolicyandRuleimplementations as security-sensitive code. - Keep fail-closed behavior; never replace an error result with the original value in an adapter.
- Review default key bindings, especially the conservative bare
idbinding, against the application's data model. - Do not use real secrets in tests, benchmarks, examples, or golden fixtures.