Skip to content

Security: kakashi-kx/apt-emulation-platform

Security

SECURITY.md

Reporting a Vulnerability

Please DO NOT file public issues for security vulnerabilities.

Instead, contact me directly:

We will:

  1. Acknowledge receipt within 48 hours
  2. Investigate and validate the issue
  3. Provide a fix within 7-14 days
  4. Release a patch and credit the reporter (if desired)

Security Best Practices

For Users

  • βœ… Always run in safe mode first: --safe-mode
  • βœ… Only use on systems you own or have permission to test
  • βœ… Review commands before execution
  • βœ… Keep the tool updated
  • βœ… Use environment variables for sensitive configs

For Developers

  • βœ… Use environment variables for secrets (.env)
  • βœ… Never commit .env files to GitHub
  • βœ… Enable rate limiting in production
  • βœ… Use proper logging for audits
  • βœ… Follow OWASP guidelines
  • βœ… Run pip-audit to check for vulnerable dependencies

Vulnerability Disclosure Policy

  • πŸ”’ Private reporting only - No public issues for security bugs
  • πŸ“ 50-day disclosure timeline - We'll fix it within 50 days
  • 🏷️ CVE assignment - We'll request CVE if needed
  • πŸ‘ Credit - We'll acknowledge your contribution

Security Contact

For urgent security issues, you can also reach me on LinkedIn:

There aren't any published security advisories