Skip to content

Security: daedalus/linux-security-audit-tool

Security

SECURITY.md

Security Policy

Supported Versions

We support the latest version of the linux-security-audit-tool. Security updates are backported to the most recent major version if critical.

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT create a public GitHub issue for security vulnerabilities
  2. Email the maintainer directly at: clavijodario@gmail.com
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

Scope

This tool performs security audits on local Linux systems. Ensure your vulnerability report relates to:

  • Code execution with elevated privileges
  • Privilege escalation vectors
  • Data exposure or credential handling
  • Input validation issues
  • Authentication/authorization bypasses

Response Timeline

  • Acknowledge receipt within 48 hours
  • Provide initial assessment within 7 days
  • Target fix timeline based on severity:
    • Critical: 24-72 hours
    • High: 1-2 weeks
    • Medium: 2-4 weeks
    • Low: Next release cycle

Disclosure

We request a reasonable disclosure timeline (30 days minimum) before public disclosure. We credit reporters in the security advisory unless requested otherwise.

There aren't any published security advisories