Skip to content

Security: vburnz/return-surface-analysis

Security

SECURITY.md

Security Policy

Reporting issues in this repository

If you find a vulnerability in code, examples, documentation, or automation in this repository, please immediately contact veronica.burnz@proton.me.

Do not open a public issue containing active exploit details, secrets, or unresolved third-party vulnerability information.

Third-party vulnerabilities

This repository is a methodology project. It is not a place to publish unresolved vulnerabilities in third-party systems.

If Return Surface Analysis helps you find a third-party issue:

  1. preserve evidence,
  2. minimize access and testing,
  3. avoid exposing user data or secrets,
  4. report through the affected party's security channel,
  5. follow coordinated disclosure,
  6. publish details only after remediation or an agreed disclosure timeline.

Safe examples

Examples in this repository should be synthetic, anonymized, or based on already-public issues.

There aren’t any published security advisories