| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
We take the security of this project seriously. If you discover a security vulnerability within the Android Security Toolkit, please follow responsible disclosure practices.
- DO NOT create a public GitHub issue for security vulnerabilities
- DO NOT disclose the vulnerability publicly before it has been addressed
- Email your findings to the maintainers with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fixes (if any)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 1 week
- Resolution Timeline: Varies based on severity
- Credit: Security researchers will be credited (unless anonymity is requested)
When using these security tools:
- Authorization: Only test systems you own or have explicit permission to test
- Environment: Use isolated test environments when possible
- Data Protection: Never expose sensitive data in logs or reports
- Updates: Keep tools updated to the latest version
- Configuration: Never commit
.envfiles or credentials
- Security vulnerabilities in the tools themselves
- Issues that could lead to unauthorized access
- Data exposure risks
- Injection vulnerabilities
- Issues in third-party dependencies (report to the respective projects)
- Social engineering
- Physical attacks
- Already known issues listed in documentation
We appreciate the security research community's efforts in keeping this project secure. Responsible disclosure helps everyone!
For security concerns, contact the maintainers through GitHub or the email specified in the repository.
Thank you for helping keep the Android Security Toolkit secure!