Skip to content

Security: iotdetective/casecapture_validation_tool

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are ordinarily applied to the most recent published release.

Version Supported
0.1.x Yes
Earlier or development builds No

Reporting a vulnerability

Please do not report suspected vulnerabilities through a public GitHub issue.

Use GitHub's private vulnerability-reporting feature when it is enabled for this repository. Open the repository's Security tab and select Report a vulnerability.

If private vulnerability reporting is unavailable, contact the repository owner privately through a verified contact method listed on the owner's GitHub profile. Do not include real evidence packages, personal information, credentials, case information, or sensitive agency information in an initial report.

Include, when available:

  • the validator version;
  • browser name and version;
  • operating system;
  • a clear description of the issue;
  • controlled reproduction steps;
  • expected and observed behavior;
  • the security impact; and
  • a sanitized demonstration package that contains no actual investigative data.

Scope

Security reports are particularly useful when they concern:

  • execution of content from a selected evidence package;
  • unintended network communication;
  • path traversal or unsafe ZIP handling;
  • incorrect hash verification;
  • a package that is reported as valid despite a reproducible integrity failure;
  • denial-of-service conditions caused by reasonably sized packages;
  • unsafe validation-report output; or
  • bypass of an intended Content Security Policy restriction.

Disclosure expectations

Please allow a reasonable opportunity to investigate and correct a confirmed vulnerability before public disclosure. Receipt of a report does not guarantee a particular resolution, release schedule, or reward.

Evidence-handling reminder

Never submit a real investigative evidence package as a public attachment. Reproduce the issue with synthetic or fully sanitized data.

There aren't any published security advisories