If you discover a security vulnerability in snowpick, please report it privately. Do not open a public GitHub issue for security problems.
Email security@bishopfox.com with:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, including a proof of concept if available.
- The version or commit of snowpick affected.
We will acknowledge your report, investigate, and keep you informed of the resolution. We ask that you give us a reasonable opportunity to address the issue before any public disclosure.
snowpick is a security testing tool. Reports about the tool's own code (for example, memory-safety issues, unsafe defaults, or crashes on untrusted input) are in scope. Findings produced by snowpick against third-party systems are not vulnerabilities in this project.
snowpick is intended for authorized security testing only. Run it only against systems you own or are explicitly authorized to assess.