This repository is public and must only contain non-sensitive app metadata and public signing keys.
Do not commit:
- private keys
- secret values
- API credentials
- seed phrases
If a signing key is compromised:
- Open an urgent PR updating the app record.
- Set compromised key status to
revoked. - Add a replacement key in
signing_keys[]if needed. - Update
updated_at. - Ensure
validate-registrypasses and merge immediately.
For repository security concerns, contact the listed app owner in the affected app record and the Metaboost maintainers through your established security contact channel.
Do not publish private incident details in public issues.