Skip to content

Security: filipi86/drogonsec

Security

SECURITY.md

Security Policy

DrogonSec is a security tool, and we take the security of the project itself seriously. We appreciate responsible disclosure of vulnerabilities.

Supported Versions

Version Supported
0.1.x Yes

Only the latest released minor version receives security fixes. Please upgrade before reporting an issue.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, use one of the following private channels:

  1. GitHub Security Advisories (preferred): open a private report through the Security tab of this repository.
  2. Email: send details to filipi.pires@filipipires.com with the subject line [DrogonSec Security].

Please include as much of the following as you can:

  • The type of issue and the component affected (engine, CLI, monitor, AI client).
  • Affected version or commit hash.
  • Step-by-step instructions to reproduce.
  • A minimal proof of concept, if available.
  • The impact, including how an attacker might exploit the issue.

Response Process

  • We will acknowledge your report within 5 business days.
  • We will provide an initial assessment and expected timeline within 10 business days.
  • We will keep you informed of remediation progress and coordinate a disclosure date with you.
  • With your permission, we will credit you in the release notes and advisory.

Scope

This policy covers the DrogonSec source code and its official release artifacts. Findings produced by DrogonSec when scanning third-party code are not vulnerabilities in DrogonSec and should be reported to the respective projects.

Thank you for helping keep DrogonSec and its users safe.

There aren't any published security advisories