The latest commit on main is supported. Older revisions may not receive security fixes.
Use GitHub's private vulnerability reporting through this repository's Security Advisories. Do not open a public issue for an undisclosed vulnerability.
Include reproduction steps, affected files or revisions, impact, and any suggested mitigation. Do not include live secrets or sensitive repository contents.
Security reports may cover scripts/scan_plan.py and documentation that instructs agents how to
plan, execute, or report scans. Vulnerabilities in third-party scanners should be reported to their
maintainers.
Maintainers aim to acknowledge reports within seven days, assess severity and scope, and provide status updates through the private advisory. Fix and disclosure timing depends on impact and coordination needs.