Skip to main content
The Termux Monorepo enforces strict security boundaries to protect credentials, session data, and the integrity of the build. This page covers the rules you must follow when handling secrets, committing files, and passing gates.

Credential rotation

Rotating credentials, API keys, or tokens requires explicit authorization from a human operator. Autonomous agents may detect expiration or exposure, but they must not perform the rotation without human approval. Document the rotation request in docs/proposals/active/<id>/ITEMS.md and obtain consensus before proceeding.

Banned artifact classes

Do not commit the following Class 3 and Class 4 artifacts to git: If you find these files in your working tree, add them to .gitignore and remove them from history before opening a PR.

ARCHW1Z gate

Every merge to master must pass the ARCHW1Z gate. The gate consists of two mandatory scripts:
Both must return exit code 0. If either fails, the merge is blocked. See the CI gates reference for full details.

Security remediation process

When a security issue is found, follow the process in docs/SECURITY-REMEDIATION.md:
1

Report

Open a private proposal or alert the human operator. Do not post secrets in public chat.
2

Assess

Classify the severity and identify affected files, credentials, or agents.
3

Remediate

Rotate exposed credentials, remove artifacts from git history, and patch the vulnerability.
4

Verify

Run both CI gates and confirm no residual exposure remains.

Tracked findings

Confirmed credential exposure findings are recorded in docs/CREDENTIAL-EXPOSURE.md. Review this file before proposing changes to secret handling or authentication flows.
If you discover a credential exposure, stop immediately. Do not commit, push, or merge until the exposure is contained and the remediation process is complete.

Next steps