Skip to content

Security: threatcode/resources

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of our resources seriously. If you discover a security vulnerability in any part of this project, please report it to us.

Responsible Disclosure

We encourage responsible disclosure. Please send your report to the project maintainers via a private email or GitHub Issue labeled security.

Do NOT report security vulnerabilities through public GitHub issues or public channels.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any proposed fixes

Supported Versions

We aim to maintain the latest versions of all resources. When security issues are found in the data or documentation, they will be addressed promptly.

Version Supported
Latest
Older

Security Notes

This project contains security research content including:

  • Anti-pattern examples for educational purposes
  • Taxonomy of attack vectors
  • Pseudocode demonstrating vulnerabilities

All content is intended for defensive security purposes only. The authors do not condone or support malicious use of any information contained herein.

Data Integrity

  • Taxonomy data is maintained as JSON source of truth (taxonomy.json)
  • All anti-pattern references cite verified sources (CVE databases, academic papers)
  • Research statistics are sourced from published studies and reports

There aren't any published security advisories