Skip to content

Security: thecrewx/shadowgate

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest major release is actively supported for security updates.

Reporting a Vulnerability

Please DO NOT report security vulnerabilities on the public issue tracker. Send an email to security@shadowgate-project.org.

What to expect

  • You will receive an acknowledgment within 48 hours.
  • We aim to fix vulnerabilities within 90 days.

Scope

  • In Scope: Core proxy, honeypot, dashboard, and alerting systems.
  • Out of Scope: Denial of Service (DoS) attacks requiring massive resources, issues in third-party dependencies (unless a patch can be practically applied in our codebase).

Hall of Fame

We publicly acknowledge security researchers who responsibly disclose vulnerabilities.

There aren't any published security advisories