SSH Log Analyzer reads untrusted text logs but does not execute their contents,
perform network requests or resolve source addresses. Input is decoded with
replacement for invalid UTF-8 and bounded by --max-lines.
Reports may contain usernames, IP addresses and event timestamps. Normalized
events are excluded from JSON unless --include-events is explicitly enabled.
Keep reports inside the relevant incident-response boundary and do not attach
real infrastructure logs to public GitHub issues.
To report a vulnerability in the analyzer, contact the repository owner privately through GitHub. Include a minimal synthetic reproducer and avoid real credentials, hostnames or customer data.