Skip to content

Security: Cogensec/caap

Security

SECURITY.md

Security policy

Do not open a public issue for a vulnerability that could make the runner escape its synthetic boundary, execute unintended code, expose credentials, contact an unauthorized target, or misclassify missing evidence as a pass.

Report security issues privately to caap@cogensec.com with:

  • affected version and component;
  • safe reproduction steps;
  • expected and observed behavior;
  • potential impact;
  • suggested remediation, if available.

Do not include real secrets, customer data, destructive payloads, or live target details. The project will acknowledge a complete report, coordinate remediation and disclosure, and credit reporters who want attribution.

Supported versions will be listed after the first release. Until then, the main branch is the only maintained line.

There aren't any published security advisories