Skip to content

Security: Stratus-Security/AIza-Audit

Security

SECURITY.md

Security

Security fixes target main and the latest release.

Reporting a vulnerability

Use Security → Report a vulnerability to send a private report. If private reporting is unavailable, open an issue asking for a private contact channel. Do not include vulnerability details in that issue.

Include the affected version and operating system, a reproduction that uses placeholders instead of credentials, the impact, and any proposed fix.

Never submit an API key, Google Cloud project ID or number, keyed request URL, or unredacted audit report. If a key was exposed during testing, rotate or revoke it before continuing.

Public bug reports and screenshots must also be scrubbed of shell history, environment variables, request URLs, JSON output, and network captures. Masked reports can still reveal project or restriction details.

Please report credential exposure, probe side effects, bypassed billing or policy gates, unsafe command-line handling, incomplete redaction, release-integrity problems, or classifications that could lead to unsafe use.

There aren't any published security advisories