Skip to content

Security: code-cartography/scalps

Security

SECURITY.md

Security policy

Report suspected vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue for a vulnerability or include sensitive details in an ordinary bug report.

Include the affected scalps version or commit, openSUSE Leap version, reproduction steps, expected impact, and any known workaround. Avoid attaching proprietary source code, compilation databases, indexes, credentials, or private paths unless the maintainers request them through the private report.

Before the first public release, only the current development revision is maintained. Beginning with 1.0.0, the latest released version will receive security fixes until a broader maintenance policy is published. Reports about unsupported environments are still useful when the same problem may affect the supported openSUSE Leap 16 environment.

Private vulnerability reporting must be enabled on the GitHub repository before its first public release.

There aren't any published security advisories