Skip to content

Security: Stunspot/TestForge

Security

SECURITY.md

Security policy

Do not open a public issue containing live credentials, private keys, customer records, exploit payloads against third parties, proprietary source code you are not authorized to share, or other sensitive material.

For ordinary defects, provide the smallest synthetic reproduction that preserves the failure through the TestForge issue tracker. For a suspected vulnerability that cannot be safely disclosed in public, request a private reporting route through Collaborative Dynamics.

TestForge's security-testing guidance requires a named target, explicit permission, non-production default, time window, rate and concurrency limits, prohibited actions, data-handling rules and a stop contact. Without those boundaries, remain in review-and-plan mode.

Public availability of this repository is not authorization to test any system.

There aren't any published security advisories