Skip to content

Security: w3nabil/red-scripts

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
a-2.x
a-1.x
a-0.x

Reporting a Vulnerability

Thank you for taking the time to improve the security of Red-Scripts by reporting a vulnerability. We appreciate your effort and are committed to addressing any security concerns promptly.

About Red-Scripts

Red-Scripts is designed to check the vulnerability of any system, server, or script. It does not store any data online; all data is saved locally on the user’s PC. This ensures user privacy and security while using the tool.

How to Report

If you discover a vulnerability in Red-Scripts, please follow these steps:

  1. Do Not Disclose Publicly

    • To protect our users, please avoid sharing details of the vulnerability publicly until it has been resolved.
  2. Contact Us Directly

    • Email your findings to: [email protected]
    • Use the subject line: Security Vulnerability Report: [Brief Description]
  3. Provide Detailed Information Include the following details in your report:

    • A clear description of the vulnerability.
    • Steps to reproduce the issue.
    • Potential impact of the vulnerability.
    • Any potential fixes or recommendations.

What Happens Next

  1. Acknowledgment

    • We will acknowledge receipt of your report within 48 hours.
  2. Investigation

    • Our security team will investigate the issue and may reach out to you for further details.
  3. Resolution

    • We aim to address all vulnerabilities promptly, typically within 90 days of initial disclosure, depending on complexity.
  4. Public Disclosure

    • Once resolved, we will coordinate with you to disclose the vulnerability responsibly. If applicable, we will credit you for your discovery.

Responsible Disclosure Policy

We encourage researchers to follow our Responsible Disclosure Policy:

  • Make a good faith effort to avoid privacy violations, destruction of data, or disruption of services.
  • Report the issue promptly and avoid publicly disclosing it until we’ve addressed it.
  • Act within the bounds of the law.

Recognition

As a token of our appreciation, we may acknowledge your contributions in our project’s release notes or security page.

Thank you for helping make Red-Scripts more secure!

There aren’t any published security advisories