Skip to content

Security: sr-maximus/Q-SECAT

Security

SECURITY.md

Security Policy

Supported version

Version Supported
0.1.x Yes

Reporting a vulnerability

Do not disclose exploitable defects publicly before maintainers can review them. Open a private GitHub Security Advisory in the repository that hosts Q-SECAT. Include affected version, impact, reproduction in a safe environment, and proposed remediation when available.

Scope

Reports may cover the CLI, schemas, catalog integrity, unsafe test language, dependency risks or documentation that could cause a materially incorrect assessment.

Q-SECAT itself does not authorize testing of third-party systems. Evidence submitted to the project must be sanitized and lawfully obtained.

There aren't any published security advisories