Only the latest major release is actively supported for security updates.
Please DO NOT report security vulnerabilities on the public issue tracker. Send an email to security@shadowgate-project.org.
- You will receive an acknowledgment within 48 hours.
- We aim to fix vulnerabilities within 90 days.
- In Scope: Core proxy, honeypot, dashboard, and alerting systems.
- Out of Scope: Denial of Service (DoS) attacks requiring massive resources, issues in third-party dependencies (unless a patch can be practically applied in our codebase).
We publicly acknowledge security researchers who responsibly disclose vulnerabilities.