This policy applies to every public repository of the ASC-IT organization, including Darkmoon.
Please do not open a public issue for a security problem.
Send a report to support@asc-it.fr with the subject [SECURITY], including:
- the repository and version (tag or commit) concerned,
- a description of the issue and its impact,
- steps or a proof of concept to reproduce it.
You will receive an acknowledgement within 3 working days. We will keep you informed of the progress and credit you in the release notes if you wish.
- Darkmoon (
ASCIT31/Dark-Moon) and its companion repositories (darkmoon-scan-action,Darkmoon-Benchmarks,darkmoon-research,Dark-Moon-CI-Demo) - The public services
dark-moon.org,docs.dark-moon.org,demo.dark-moon.org,portal.dark-moon.organdasc-it.fr
Darkmoon is an offensive security tool. Findings produced by Darkmoon against third-party targets are out of scope here: only test systems you are authorized to assess, and report those findings to their owners.
Security fixes are shipped on the latest release of each repository.