Skip to content

Security: cmahmud/synsec

Security

SECURITY.md

Security Policy

SynSec is security software and may itself handle sensitive repositories, credentials, findings, and vulnerability data. Please avoid opening a public issue for a vulnerability that could put users at risk.

Reporting a vulnerability

For now, contact the repository owner privately through an appropriate private channel rather than publishing exploit details in a GitHub issue.

A dedicated security-reporting address and GitHub private vulnerability reporting policy will be added before the first public release.

Scope

Useful reports include vulnerabilities in SynSec itself, unsafe handling of repositories under analysis, credential exposure, sandbox escapes, command execution issues, path traversal, authorization failures, and weaknesses that could expose private scan data.

There aren't any published security advisories