We provide security updates for the following versions of our projects:
| Project | Version | Supported |
|---|---|---|
| ScanCode Toolkit | >= 32.0.0 | ✅ |
| ScanCode.io | >= 32.0.0 | ✅ |
| VulnerableCode | >= 32.0.0 | ✅ |
| AboutCode Toolkit | >= 32.0.0 | ✅ |
IMPORTANT: Do not publicly disclose security vulnerabilities. Instead, please email [email protected] with details.
We take the security of our software seriously. If you believe you've found a security vulnerability, please follow these steps:
- Email your findings to [email protected]
- Include as much information as possible about the vulnerability
- Do not disclose the vulnerability publicly until it has been addressed
- We will acknowledge receipt of your vulnerability report within 48 hours
- We will provide a more detailed response within 7 days indicating the next steps
- Initial Response: We will acknowledge receipt of your report within 48 hours
- Verification: Our security team will verify the vulnerability
- Fix Development: We will develop a fix for the vulnerability
- Testing: The fix will be thoroughly tested
- Release: A new version will be released with the fix
- Disclosure: We will coordinate public disclosure with you
Security updates are released as new versions of our software. We recommend always using the latest version of our tools.
Our security team consists of core maintainers and security experts who review and address security reports.
We appreciate the efforts of security researchers who help us keep our software secure. We will acknowledge your contribution in our security advisories unless you request otherwise.
- All code changes are reviewed by at least one maintainer
- We use automated security scanning tools in our CI/CD pipeline
- Dependencies are regularly audited and updated
- We follow secure coding practices and guidelines
- We do not store sensitive user data
- All data processing is done locally unless explicitly configured otherwise
- API keys and credentials are never stored in the codebase
- We use environment variables for sensitive configuration
- Regular security updates are applied to our infrastructure
- Access to production systems is restricted and monitored
- We use secure communication protocols (HTTPS, SSH)
- Regular security audits are performed
We believe in responsible disclosure and will work with security researchers to address vulnerabilities in a timely manner. We will not take legal action against security researchers who report vulnerabilities according to this policy.
- Primary: [email protected]
- Backup: [email protected]