Please report security issues privately to security@jungherz.com rather than opening a public issue. We aim to acknowledge within three working days.
- StripeJack reads a Stripe secret key from the environment. A restricted key (
rk_live_…) with read access to balance transactions, charges, payouts, customers, invoices, credit notes, prices and account is sufficient — the tool never writes to Stripe, and needs no access to payment intents, subscriptions, disputes or webhooks. The full list is indocs/configuration.md. - Credentials are never written to the log. The logger masks values that look like keys, tokens or passwords wherever they appear in a record, so a call site cannot leak one by logging a config object.
.envis gitignored, andstripe-jack initcreates it with mode600. Verify withgit check-ignore -v .envbefore your first commit.
Exports contain customer names, addresses and invoice PDFs.
- Nothing produced by a run is committed:
out/,*.zipandtest/fixtures/real/are gitignored. - The test fixture in
test/fixtures/anonymized/is generated byscripts/anonymize-fixture.ts, which replaces every name, address, email, tax id and Stripe identifier with a deterministic pseudonym of the same length. Balance-transaction sources are reduced to a field whitelist, so nested payer details cannot survive. - Mailing an export sends customer data to an external server. It is off by default.
Only the latest released version receives fixes.