Skip to content

Security: arghosh/difa

Security

SECURITY.md

Security Policy

Supported versions

This repository is research code. Security fixes are best-effort on the default branch.

Reporting a vulnerability

Please open a private security advisory on GitHub if possible. If private reporting is not available, open an issue without disclosing exploit details and request a private follow-up channel.

Scope

In scope:

  • Credential leakage in scripts/docs
  • Unsafe defaults that expose user data

Out of scope:

  • Vulnerabilities in third-party dependencies (report upstream first)

There aren't any published security advisories