Sighthound is pre-1.0. Security fixes target the latest main and the most
recent 0.1.x release.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
Please report security vulnerabilities in Sighthound itself privately.
- Preferred: GitHub private vulnerability reporting — open a report under this repository's Security → Report a vulnerability tab.
- Alternate: email
security@corgea.com.
Please include a description, reproduction steps, affected version or commit, and impact. We aim to acknowledge reports within 5 business days and will coordinate a fix and disclosure timeline with you.
We ask that you give us a reasonable opportunity to address the issue before any public disclosure (coordinated disclosure).
This policy covers vulnerabilities in Sighthound itself (the scanner and its distribution). It does not cover findings that Sighthound reports in the code you scan — those are outputs of the tool, not vulnerabilities in the tool.