Skip to content

Security: whatisproblem/patchrank

Security

SECURITY.md

Security Policy

Supported Scope

Security reports are welcome for:

  • Incorrect handling of local report files.
  • Unsafe network behavior in enrichment features.
  • Output that could leak private report content unexpectedly.
  • Supply-chain issues in CI or packaging metadata.

Patchrank does not require credentials. Please do not include private scanner reports, tokens, or customer system details in public issues.

Reporting

Use GitHub private security advisories when available. Otherwise, open an issue with a minimal synthetic reproduction.

There aren't any published security advisories