Skip to content

Security: Meisterware/detektor

Security

SECURITY.md

Security Policy

Reporting Security Issues

If you discover a security vulnerability related to:

  • the Detektor scanner
  • example artifacts included in this repository
  • reference implementations maintained by Meisterware

please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, report the issue privately by emailing:

security@meisterware.com

Please include the following information if possible:

  • description of the vulnerability
  • affected component or file
  • steps to reproduce the issue
  • potential impact or exploitation scenario
  • suggested mitigation (if known)

Including sample files or minimal reproduction examples is helpful.

For faster triage, please include the following in the email subject:

[Detektor Security]

We will acknowledge receipt of the report and investigate as soon as possible.


Scope

This policy applies to:

  • the Detektor scanner repository
  • example artifacts provided in this repository
  • official reference implementations maintained by Meisterware

Issues related to the OpenPAKT specification itself should normally be reported through the OpenPAKT specification repository, unless they represent a security vulnerability.


Responsible Disclosure

We encourage responsible disclosure and will work with reporters to:

  1. confirm the issue
  2. assess the impact
  3. prepare mitigation guidance
  4. coordinate disclosure and release of fixes

We ask that reporters avoid public disclosure until a fix or mitigation is available.


Supported Versions

Security fixes are typically applied to the latest released version of Detektor.

Older versions may not receive security updates.


Acknowledgements

We appreciate responsible security research that helps improve the reliability and safety of the Detektor ecosystem.

With the reporter’s permission, valid reports may be acknowledged in project release notes or documentation.

There aren’t any published security advisories