Please do not report security issues through public GitHub issues.
Use GitHub private vulnerability reporting for this repository when available.
If private reporting is not available in your environment, contact the maintainers through repository administration channels and include:
- a clear description of the issue
- affected components
- steps to reproduce
- expected impact
- any suggested remediation
Security reports should focus on vulnerabilities in RepoScan itself, including:
- unsafe handling of secrets
- command execution risks
- repository import or clone logic with security impact
- data exposure caused by RepoScan behavior
RepoScan is a repository discovery and clone tool. It is not a vulnerability scanner.
We prefer coordinated disclosure. Please allow maintainers reasonable time to reproduce, assess, and fix reported issues before public disclosure.