| Version | Support status |
|---|---|
v0.0.3 |
Supported |
v0.0.2 |
Not supported |
v0.0.1 |
Not supported |
Support window: latest tagged release on main is supported for coordinated disclosure and fixes.
Do not open public issues for exploitable defects that could impact users directly.
Preferred workflow:
- Open a private GitHub Security Advisory draft in this repository, or contact maintainers privately.
- Include reproducible steps, impact, and affected files.
- Provide telemetry snippets if available (
commands/findings/loot) with sensitive values redacted. - Include exact version/commit (
h3retik version, git SHA, runtime image tag).
- Initial triage: within
72h - Severity assessment + CWE/CVSS classification: within
7d - Mitigation plan: within
14dfor high/critical confirmed issues - Coordinated disclosure timeline agreed with reporter before public release
Contributors should prioritize:
- target-agnostic controls over target-specific shortcuts
- safe defaults in command generation
- explicit OPSEC risk signaling for noisy/destructive actions
- strict telemetry integrity (no fabricated/implicit success states)