If you discover a security vulnerability in Malware Detector, do not open a public GitHub issue. Report it privately.
Report via GitHub Security Advisory:
- Go to the repository's Security tab
- Click Report a vulnerability (or use
https://github.com/Dev9269/malware-detector/security/advisories/new) - Fill in the details
Or email directly:
jainammaru567000@gmail.com
GPG fingerprint: 00D6CCEA36D10407
- Type of vulnerability
- Steps to reproduce (PoC preferred)
- Affected versions
- Potential impact
- Any suggested fix (optional)
| Step | Timeframe |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix timeline | Communicated based on severity |
| Coordinated disclosure | 90 days after fix shipped |
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
This policy covers the source code, ML pipeline, and API in this repository. The ML model (LightGBM) is trained on synthetic data — model poisoning or adversarial evasion should be reported under this policy. Dependencies (scikit-learn, FastAPI, etc.) should be reported to their respective maintainers.
We follow coordinated disclosure. Please allow us reasonable time to fix the issue before any public disclosure. We will credit reporters in release notes (with permission).