V Vant Docs

Tutorial: Security Best Practices

Secure your Vant installation

Token Security

Don’t Commit Tokens

# Add to .gitignore
echo ".env" >> .gitignore
echo "*.token" >> .gitignore

Use GitHub Fine-Grained Tokens

Create at: github.com/settings/tokens

Required permissions:

# Create token with minimal scope
# Only give repo access, not entire account

Network Security

Use HTTPS Only

# Always use HTTPS for remote
export GITHUB_REPO=https://github.com/user/repo

Firewall

# Block non-essential ports
ufw default deny incoming
ufw allow 3456/tcp  # Vant only

Sandbox

Enable Sandbox

const sandbox = require('vant').sandbox;

const s = sandbox.create({
    canRead: true,
    canWrite: true,
    canNetwork: false,  // Disable network
    canExec: false     // Disable exec
});

VAF

Configure VAF

const vaf = require('./lib/vaf');

vaf.configure({
    maxLength: 50000,
    blockPathTraversal: true,
    blockShellChars: true,
    blockEnvVars: true
});

More

See Security and VAF.