Report privately through GitHub Security Advisories. Please do not open a public issue for a vulnerability.
Worth knowing before you run it, because it does more than read files:
- It sends payloads to whatever URL you point it at, some of them deliberately malformed — invalid UTF-8, embedded NULs, hundred-thousand character tokens, integers at the edge of the range. That is the point of the corpus. Point it at a store you are willing to have written to.
- It writes to that store, and with
teardowndeclared it deletes the stream or index a case uses before each case. Every adapter in this repository scopes that to aspecmatrix_-prefixed name derived from the case id, but read the adapter before running it against anything you care about. --managerunsdockerto start and remove containers namedspecmatrix-<backend>, and removes any existing container of that name first.- It does not phone home. There is no telemetry, no upload, and no network access beyond the backend URL you give it and the container images Docker pulls.
A vulnerability here means something like: a case payload that can escape the runner, an adapter field that can execute or inject beyond the request it describes, a rendered page that executes content it was given, or a dependency advisory that reaches this code.
A backend behaving badly is not a vulnerability in this project — it is a
finding, and it goes through
CONTRIBUTING.md to that backend's own tracker.
- Pull requests only on
main; no direct pushes, no force pushes, no deletion - Review required from a code owner, and CI green, before merge
- GitHub Actions run with a read-only token and are pinned to commit SHAs, so a moved tag cannot change what runs
cargo auditon every pull request- Dependabot on both Cargo and Actions, weekly
- Secret scanning with push protection
cases/ contains payloads that are malformed on purpose, including bytes that
are not valid UTF-8. Some scanners flag them. They are fixtures, they are never
executed, and each one is described by the check beside it.