Zen-AI-Pentest folgt strikten Sicherheitsstandards:
- ✅ Alle Code-Änderungen durch Pre-commit Hooks
- ✅ Automatische Snyk Scans bei jedem Push
- ✅ CodeQL Analyse für statische Code-Analyse
- ✅ CI Pipeline mit Ruff, Flake8, und Tests
- ✅ Private IP Blocking für alle Tools
- ✅ Docker Sandbox für Tool-Ausführung
Letzter Scan: 2026-07-21
✅ CI: All checks passing
✅ Pre-commit CI: All checks passing
✅ Security Workflow: All checks passing
✅ CodeQL: All checks passing
✅ Dependabot: All alerts fixed/dismissed
- CodeQL: Bei jedem Push & PR
- Pre-commit Hooks: Ruff, trailing-whitespace, EOF-fixer, YAML/JSON/TomL checks
- CI Pipeline: Ruff format + lint, Flake8, Python-Tests (3.12, 3.13)
Nicht öffentlich melden!
Bei Sicherheitsvorfällen:
- Security Advisory erstellen (privat)
- Oder Email: shadd0wtaka@protonmail.com
- Pre-commit Hooks (black, isort, flake8, bandit)
- Secret Detection (detect-secrets)
- Type Checking (mypy)
- Snyk Monitoring
- pip-audit Scans
- Automated Dependabot Updates
- Docker Sandbox für alle Tools
- Private IP Blocking
- Resource Limits (CPU, Memory, Time)
- Read-only Filesysteme
- ✅ OpenSSF Best Practices (passing)
- ✅ CodeQL aktiviert
- ✅ Dependabot aktiviert
- ✅ Snyk aktiviert
- ✅ Branch Protection für main
- ✅ SECURITY.md vorhanden
We follow a Coordinated Vulnerability Disclosure process:
- Report - Send details to shadd0wtaka@protonmail.com
- Acknowledge - We confirm receipt within 48 hours
- Coordinate - We work with reporters on timeline/fixes
- Disclosure - Public release after patch availability
- Initial response: 48 hours
- Severity assessment: 7 days
- Fix timeline: Based on severity (critical: 30 days, high: 60 days, medium: 90 days)
- Coordinated disclosure: After patch release
- Authentication bypasses
- Code injection vulnerabilities
- Data exposure
- Privilege escalation
- Any other security-relevant issues
Researchers who act in good faith are protected under our disclosure policy.
Letzte Aktualisierung: 2026-04-05
Nächste Review: 2026-05-04
Status: ✅ Major vulnerabilities resolved |