Skip to content

Security: BishopFox/snowpick

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in snowpick, please report it privately. Do not open a public GitHub issue for security problems.

Email security@bishopfox.com with:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, including a proof of concept if available.
  • The version or commit of snowpick affected.

We will acknowledge your report, investigate, and keep you informed of the resolution. We ask that you give us a reasonable opportunity to address the issue before any public disclosure.

Scope

snowpick is a security testing tool. Reports about the tool's own code (for example, memory-safety issues, unsafe defaults, or crashes on untrusted input) are in scope. Findings produced by snowpick against third-party systems are not vulnerabilities in this project.

Responsible use

snowpick is intended for authorized security testing only. Run it only against systems you own or are explicitly authorized to assess.

There aren't any published security advisories