Skip to content

Security: JUNGHERZ/StripeJack

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately to security@jungherz.com rather than opening a public issue. We aim to acknowledge within three working days.

Handling of credentials

  • StripeJack reads a Stripe secret key from the environment. A restricted key (rk_live_…) with read access to balance transactions, charges, payouts, customers, invoices, credit notes, prices and account is sufficient — the tool never writes to Stripe, and needs no access to payment intents, subscriptions, disputes or webhooks. The full list is in docs/configuration.md.
  • Credentials are never written to the log. The logger masks values that look like keys, tokens or passwords wherever they appear in a record, so a call site cannot leak one by logging a config object.
  • .env is gitignored, and stripe-jack init creates it with mode 600. Verify with git check-ignore -v .env before your first commit.

Handling of customer data

Exports contain customer names, addresses and invoice PDFs.

  • Nothing produced by a run is committed: out/, *.zip and test/fixtures/real/ are gitignored.
  • The test fixture in test/fixtures/anonymized/ is generated by scripts/anonymize-fixture.ts, which replaces every name, address, email, tax id and Stripe identifier with a deterministic pseudonym of the same length. Balance-transaction sources are reduced to a field whitelist, so nested payer details cannot survive.
  • Mailing an export sends customer data to an external server. It is off by default.

Supported versions

Only the latest released version receives fixes.

There aren't any published security advisories