Skip to content

Security: CyberAuth/Secret-Scanner

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities through a private GitHub Security Advisory for this repository. Do not open a public issue containing exploit details, credentials, customer names, private repository paths, or scanner output.

Include a minimal reproduction using synthetic data, the affected version or commit, and the expected security impact. Maintainers will acknowledge the report and coordinate disclosure through the advisory.

Handling scan data

Results produced by this project are outside the scope of public issue tracking. If a scan identifies an exposed credential, rotate or revoke it using the affected provider's incident-response process. Do not submit the secret or the raw report to this repository.

Only scan data and systems you are authorized to assess. Live verification can make outbound requests and should be enabled only with explicit authorization.

There aren't any published security advisories