Please DO NOT file public issues for security vulnerabilities.
Instead, contact me directly:
- π§ Email: kakashi4kx@gmail.com
- π GitHub: Create a private security advisory
We will:
- Acknowledge receipt within 48 hours
- Investigate and validate the issue
- Provide a fix within 7-14 days
- Release a patch and credit the reporter (if desired)
- β
Always run in safe mode first:
--safe-mode - β Only use on systems you own or have permission to test
- β Review commands before execution
- β Keep the tool updated
- β Use environment variables for sensitive configs
- β
Use environment variables for secrets (
.env) - β
Never commit
.envfiles to GitHub - β Enable rate limiting in production
- β Use proper logging for audits
- β Follow OWASP guidelines
- β
Run
pip-auditto check for vulnerable dependencies
- π Private reporting only - No public issues for security bugs
- π 50-day disclosure timeline - We'll fix it within 50 days
- π·οΈ CVE assignment - We'll request CVE if needed
- π Credit - We'll acknowledge your contribution
For urgent security issues, you can also reach me on LinkedIn:
- π Abhijith S