SecScanMonitor is security software and treats reports as private by default.
Please use GitHub’s private vulnerability reporting for this repository when it is available. Do not open a public issue for an undisclosed vulnerability, and do not include credentials, private keys, personal data, client material, or raw evidence in a report. If private reporting is unavailable, contact the maintainers through a private channel before disclosure.
Include a concise description, affected revision or path, reproduction steps that do not access a live target, impact, and any safe mitigation. Redact secrets and personal data before sending material.
There is no guaranteed response time or service-level agreement. The maintainers will acknowledge receipt when practicable, validate only what they can reproduce, and document limitations rather than claiming unsupported certainty.
Supported security posture:
- The default authority is inspection-only.
- No public workflow should receive production credentials.
- Findings require evidence and adjudication.
- Raw evidence and secret values are outside the public repository boundary.