Thank you for helping keep mini-scanner secure.
We take security vulnerabilities seriously and appreciate responsible disclosure from the community.
| Version | Supported |
|---|---|
| 1.x | ✅ Yes |
| < 1.0 | ❌ No |
Only the latest stable release receives security updates.
Please do not create a public GitHub issue for security vulnerabilities.
Instead:
- Open a GitHub Security Advisory (preferred), if enabled.
- If unavailable, contact the maintainer privately.
- Include as much technical detail as possible.
Please include:
- A clear description of the issue
- Steps to reproduce
- A proof of concept (if possible)
- Impact assessment
- Affected versions
- Suggested mitigation (optional)
We aim to:
- Acknowledge reports within 3 business days
- Provide an initial assessment within 7 business days
- Keep the reporter informed throughout the investigation
- Release a fix as quickly as practical
Complex vulnerabilities may require additional time.
Examples of issues within scope include:
- Remote Code Execution (RCE)
- Command Injection
- Directory Traversal
- Arbitrary File Read/Write
- Authentication Bypass
- Privilege Escalation
- Information Disclosure
- Denial of Service (DoS)
- Dependency-related vulnerabilities
- Supply chain attacks
The following generally do not qualify as security vulnerabilities:
- Typographical errors
- Documentation improvements
- Code style issues
- Requests for unsupported features
- Reports affecting unsupported versions
- Theoretical attacks without a practical impact
Please:
- Allow time for investigation before public disclosure.
- Avoid accessing or modifying data that does not belong to you.
- Avoid actions that could disrupt services or other users.
- Provide sufficient information to reproduce the issue.
We appreciate responsible security research.
Contributors who responsibly disclose valid vulnerabilities may be acknowledged in release notes or project documentation, subject to their preference.
Thank you for helping improve the security of mini-scanner.