Skip to content

Security: Kevin-Umali/repyy

SECURITY.md

Security

Use GitHub's Report a vulnerability option if you find a security problem in repyy itself. Examples include target code being executed, access outside the target directory, a secret being printed without redaction, sandbox escape, unsafe Git behavior, or an incomplete scan being reported as clean.

Please do not post those details in a public issue before a fix is available. Include the affected version, operating system, impact, reproduction command, and the smallest safe fixture you can provide. Do not send live credentials, private source code, weaponized malware samples, or details that would let someone attack a third-party repository.

False positives and missed-detection ideas can use the public issue templates. Use the public issue tracker only after checking that the report does not expose a vulnerability. Only the latest released version is supported.

There aren't any published security advisories