Skip to content

Security: fant3k/ssh-log-analyzer

Security

SECURITY.md

Security policy

SSH Log Analyzer reads untrusted text logs but does not execute their contents, perform network requests or resolve source addresses. Input is decoded with replacement for invalid UTF-8 and bounded by --max-lines.

Reports may contain usernames, IP addresses and event timestamps. Normalized events are excluded from JSON unless --include-events is explicitly enabled. Keep reports inside the relevant incident-response boundary and do not attach real infrastructure logs to public GitHub issues.

To report a vulnerability in the analyzer, contact the repository owner privately through GitHub. Include a minimal synthetic reproducer and avoid real credentials, hostnames or customer data.

There aren't any published security advisories