Skip to content

Security: ateeqdesktop-dot/scopemap

Security

SECURITY.md

Security Policy

ScopeMap parses untrusted OpenAPI documents. It uses safe YAML loading, caps inputs at 10 MiB, never performs network calls, and never executes API operations or tokens.

Reports may repeat domains, routes, and scope names from the input. Review them before sharing. A finding is a specification-level signal, not proof of a runtime authorization flaw.

Please report vulnerabilities privately through GitHub Security Advisories. Do not publish confidential API specifications or credentials in issues.

There aren't any published security advisories