Skip to content

Security: SHAdd0WTAka/Zen-Ai-Pentest

SECURITY.md

Security Policy

Sicherheitsstandards

Zen-AI-Pentest folgt strikten Sicherheitsstandards:

  • ✅ Alle Code-Änderungen durch Pre-commit Hooks
  • ✅ Automatische Snyk Scans bei jedem Push
  • ✅ CodeQL Analyse für statische Code-Analyse
  • ✅ CI Pipeline mit Ruff, Flake8, und Tests
  • ✅ Private IP Blocking für alle Tools
  • ✅ Docker Sandbox für Tool-Ausführung

Aktuelle Sicherheitslage

Sicherheitsstatus: ✅ CLEAN

Letzter Scan: 2026-07-21

✅ CI: All checks passing
✅ Pre-commit CI: All checks passing
✅ Security Workflow: All checks passing
✅ CodeQL: All checks passing
✅ Dependabot: All alerts fixed/dismissed

Monitoring

Automatische Scans

  • CodeQL: Bei jedem Push & PR
  • Pre-commit Hooks: Ruff, trailing-whitespace, EOF-fixer, YAML/JSON/TomL checks
  • CI Pipeline: Ruff format + lint, Flake8, Python-Tests (3.12, 3.13)

Dashboards

Melden von Sicherheitsproblemen

Nicht öffentlich melden!

Bei Sicherheitsvorfällen:

  1. Security Advisory erstellen (privat)
  2. Oder Email: shadd0wtaka@protonmail.com

Sicherheitsmaßnahmen

Code-Sicherheit

  • Pre-commit Hooks (black, isort, flake8, bandit)
  • Secret Detection (detect-secrets)
  • Type Checking (mypy)

Dependency-Sicherheit

  • Snyk Monitoring
  • pip-audit Scans
  • Automated Dependabot Updates

Runtime-Sicherheit

  • Docker Sandbox für alle Tools
  • Private IP Blocking
  • Resource Limits (CPU, Memory, Time)
  • Read-only Filesysteme

Compliance

  • ✅ OpenSSF Best Practices (passing)
  • ✅ CodeQL aktiviert
  • ✅ Dependabot aktiviert
  • ✅ Snyk aktiviert
  • ✅ Branch Protection für main
  • ✅ SECURITY.md vorhanden

Coordinated Vulnerability Disclosure (CVD)

Policy

We follow a Coordinated Vulnerability Disclosure process:

  1. Report - Send details to shadd0wtaka@protonmail.com
  2. Acknowledge - We confirm receipt within 48 hours
  3. Coordinate - We work with reporters on timeline/fixes
  4. Disclosure - Public release after patch availability

Disclosure Timeline

  • Initial response: 48 hours
  • Severity assessment: 7 days
  • Fix timeline: Based on severity (critical: 30 days, high: 60 days, medium: 90 days)
  • Coordinated disclosure: After patch release

Scope

  • Authentication bypasses
  • Code injection vulnerabilities
  • Data exposure
  • Privilege escalation
  • Any other security-relevant issues

Safe Harbor

Researchers who act in good faith are protected under our disclosure policy.


Letzte Aktualisierung: 2026-04-05 Nächste Review: 2026-05-04 Status: ✅ Major vulnerabilities resolved | ⚠️ 6 transitive dependencies (lodash from codecov/anchore)

Learn more about advisories related to SHAdd0WTAka/Zen-Ai-Pentest in the GitHub Advisory Database