Skip to content

Security: spideydotjs/gengar

Security

SECURITY.md

Security Policy

🛡️ Supported Versions

We actively maintain and provide security updates for the following versions of Gengar:

Version Supported
1.x.x ✅
< 1.0.0 ❌

🚨 Reporting a Vulnerability

The Gengar team and contributors take the security and privacy of researchers very seriously. Because Gengar interacts with Tor circuits, hidden services, and unhosted network endpoints, we prioritize prompt resolution of security vulnerabilities.

Responsible Disclosure Guidelines

  • Do not open public GitHub issues for suspected security vulnerabilities or zero-day disclosures.
  • Please report vulnerabilities privately by emailing the maintainer or opening a GitHub Private Vulnerability Report.
  • Provide detailed steps to reproduce the vulnerability, including:
    • Affected endpoint or module
    • Proof-of-concept payload or script
    • Expected vs. actual behavior
    • Environment details (Node.js version, OS, Docker/Local)

Our Commitment

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We will provide a timeline for assessing the severity and releasing a patch.
  • We will credit reporters publicly in the release notes (unless anonymity is requested).

⚖️ Legal & Ethical Notice

Gengar is built strictly for educational, authorized research, and lawful OSINT purposes. Maintaining user privacy and network integrity across Tor circuits is a core design principle.

There aren't any published security advisories