Skip to content

Security: Litju/Sec-Scan-Monitor

SECURITY.md

Security policy

SecScanMonitor is security software and treats reports as private by default.

Please use GitHub’s private vulnerability reporting for this repository when it is available. Do not open a public issue for an undisclosed vulnerability, and do not include credentials, private keys, personal data, client material, or raw evidence in a report. If private reporting is unavailable, contact the maintainers through a private channel before disclosure.

Include a concise description, affected revision or path, reproduction steps that do not access a live target, impact, and any safe mitigation. Redact secrets and personal data before sending material.

There is no guaranteed response time or service-level agreement. The maintainers will acknowledge receipt when practicable, validate only what they can reproduce, and document limitations rather than claiming unsupported certainty.

Supported security posture:

  • The default authority is inspection-only.
  • No public workflow should receive production credentials.
  • Findings require evidence and adjudication.
  • Raw evidence and secret values are outside the public repository boundary.

There aren't any published security advisories