If you discover a security vulnerability in Zero Trust Lab, do not open a public GitHub issue. Report it privately.
Report via GitHub Security Advisory:
- Go to the repository's Security tab
- Click Report a vulnerability (or use
https://github.com/Dev9269/zero-trust-lab/security/advisories/new) - Fill in the details
Or email directly:
jainammaru567000@gmail.com
GPG fingerprint: 00D6CCEA36D10407
- Type of vulnerability
- Steps to reproduce (PoC preferred)
- Affected versions
- Potential impact
- Any suggested fix (optional)
| Step | Timeframe |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix timeline | Communicated based on severity |
| Coordinated disclosure | 90 days after fix shipped |
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
This policy covers the gateway, authorization bridge, SSH setup, and deployment configurations in this repository. This is a lab/learning environment — do not deploy untrusted configurations to production.
We follow coordinated disclosure. Please allow us reasonable time to fix the issue before any public disclosure. We will credit reporters in release notes (with permission).