Skip to content

Security: fevra-dev/Argus

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x

Reporting a Vulnerability

If you discover a security vulnerability within Argus, please send an email to fev.dev@proton.me.

What to include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Any suggested fixes (optional but appreciated)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Target: Within 30 days (depending on severity)

What to Expect

  1. Acknowledgment: We will acknowledge receipt of your report
  2. Assessment: We will assess the vulnerability and its impact
  3. Communication: We will keep you informed of our progress
  4. Credit: If desired, we will credit you in the release notes

Security Best Practices

When using Argus:

✅ Do

  • Only scan networks you own or have explicit written permission to test
  • Keep your Argus installation updated
  • Use environment variables for sensitive configuration (API keys)
  • Review scan results before sharing (may contain sensitive data)
  • Follow responsible disclosure practices

❌ Don't

  • Scan networks without authorization
  • Store credentials in version-controlled files
  • Share scan reports publicly without sanitizing sensitive data
  • Use Argus for malicious purposes

Legal Disclaimer

Argus is designed for authorized security testing only. Unauthorized use of this tool may violate local, state, national, and international laws. Users are solely responsible for ensuring they have proper authorization before conducting any security assessments.

The author is not responsible for any misuse or damage caused by this tool.


Contact: fev.dev@proton.me

There aren’t any published security advisories