Skip to content

Security: Dev9269/malware-detector

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Malware Detector, do not open a public GitHub issue. Report it privately.

Report via GitHub Security Advisory:

  1. Go to the repository's Security tab
  2. Click Report a vulnerability (or use https://github.com/Dev9269/malware-detector/security/advisories/new)
  3. Fill in the details

Or email directly: jainammaru567000@gmail.com GPG fingerprint: 00D6CCEA36D10407

Please include:

  • Type of vulnerability
  • Steps to reproduce (PoC preferred)
  • Affected versions
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

Step Timeframe
Acknowledgment Within 48 hours
Initial assessment Within 5 business days
Fix timeline Communicated based on severity
Coordinated disclosure 90 days after fix shipped

Supported Versions

Version Supported
latest
older

Scope

This policy covers the source code, ML pipeline, and API in this repository. The ML model (LightGBM) is trained on synthetic data — model poisoning or adversarial evasion should be reported under this policy. Dependencies (scikit-learn, FastAPI, etc.) should be reported to their respective maintainers.

Coordinated Disclosure

We follow coordinated disclosure. Please allow us reasonable time to fix the issue before any public disclosure. We will credit reporters in release notes (with permission).

There aren't any published security advisories