| Version | Supported |
|---|---|
| 1.9.x | Yes |
| 1.0.x – 1.8.x | Best effort |
| 0.10.x – 0.15.x | Best effort |
| < 0.10 | No |
If you find a security issue in Bucket Scanner, please do not open a public GitHub issue with exploit details.
Contact the maintainer with:
- Description of the issue
- Steps to reproduce
- Impact assessment
- Suggested fix (optional)
We aim to acknowledge reports within 72 hours.
- Metadata by default — scans use cloud APIs for bucket settings; no bulk object exfiltration.
- Probe is explicit —
--probeperforms anonymous HTTP reachability checks only; no redirect follow; never downloads object bodies. - Redaction — reports sanitize tokens, key material, and sensitive URLs before emit (human, JSON, SARIF).
- Credential isolation — Yandex credentials resolve from
YC_*env vars only (notAWS_*aliases). - Webhook safety — notification URLs must use
httporhttpsschemes. - Demo data — examples use clearly labeled fake credentials and bucket names.
See AUDIT.md for the latest automated audit results.
Bucket Scanner scans your cloud configuration with credentials you provide. It is not a SaaS and does not phone home.