Skip to content

Security: Rohit30Confluence/mini-scanner

.github/SECURITY.md

Security Policy

Thank you for helping keep mini-scanner secure.

We take security vulnerabilities seriously and appreciate responsible disclosure from the community.


Supported Versions

Version Supported
1.x ✅ Yes
< 1.0 ❌ No

Only the latest stable release receives security updates.


Reporting a Vulnerability

Please do not create a public GitHub issue for security vulnerabilities.

Instead:

  1. Open a GitHub Security Advisory (preferred), if enabled.
  2. If unavailable, contact the maintainer privately.
  3. Include as much technical detail as possible.

Please include:

  • A clear description of the issue
  • Steps to reproduce
  • A proof of concept (if possible)
  • Impact assessment
  • Affected versions
  • Suggested mitigation (optional)

Response Timeline

We aim to:

  • Acknowledge reports within 3 business days
  • Provide an initial assessment within 7 business days
  • Keep the reporter informed throughout the investigation
  • Release a fix as quickly as practical

Complex vulnerabilities may require additional time.


Scope

Examples of issues within scope include:

  • Remote Code Execution (RCE)
  • Command Injection
  • Directory Traversal
  • Arbitrary File Read/Write
  • Authentication Bypass
  • Privilege Escalation
  • Information Disclosure
  • Denial of Service (DoS)
  • Dependency-related vulnerabilities
  • Supply chain attacks

Out of Scope

The following generally do not qualify as security vulnerabilities:

  • Typographical errors
  • Documentation improvements
  • Code style issues
  • Requests for unsupported features
  • Reports affecting unsupported versions
  • Theoretical attacks without a practical impact

Responsible Disclosure

Please:

  • Allow time for investigation before public disclosure.
  • Avoid accessing or modifying data that does not belong to you.
  • Avoid actions that could disrupt services or other users.
  • Provide sufficient information to reproduce the issue.

Recognition

We appreciate responsible security research.

Contributors who responsibly disclose valid vulnerabilities may be acknowledged in release notes or project documentation, subject to their preference.

Thank you for helping improve the security of mini-scanner.

There aren't any published security advisories