DrogonSec is a security tool, and we take the security of the project itself seriously. We appreciate responsible disclosure of vulnerabilities.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Only the latest released minor version receives security fixes. Please upgrade before reporting an issue.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use one of the following private channels:
- GitHub Security Advisories (preferred): open a private report through the Security tab of this repository.
- Email: send details to filipi.pires@filipipires.com with the subject
line
[DrogonSec Security].
Please include as much of the following as you can:
- The type of issue and the component affected (engine, CLI, monitor, AI client).
- Affected version or commit hash.
- Step-by-step instructions to reproduce.
- A minimal proof of concept, if available.
- The impact, including how an attacker might exploit the issue.
- We will acknowledge your report within 5 business days.
- We will provide an initial assessment and expected timeline within 10 business days.
- We will keep you informed of remediation progress and coordinate a disclosure date with you.
- With your permission, we will credit you in the release notes and advisory.
This policy covers the DrogonSec source code and its official release artifacts. Findings produced by DrogonSec when scanning third-party code are not vulnerabilities in DrogonSec and should be reported to the respective projects.
Thank you for helping keep DrogonSec and its users safe.