This policy covers every repository in the CatNet ecosystem:
| Repository | Role |
|---|---|
engine |
Shared Go scanning engine |
catnet |
CLI |
app |
Desktop GUI (Wails + React) |
tui |
Terminal UI (Bubble Tea) |
Only the latest release of each repository receives security updates.
Do not open a public issue for a security vulnerability.
Report it privately through either channel:
- GitHub Security Advisories — open a private report (preferred)
- Email — [email protected]
Please include the affected repository and version, reproduction steps, and the impact you observed. Expect an acknowledgement within 5 business days.
Fixes are developed privately and released before public disclosure. Reporters are credited in the advisory unless they ask otherwise.
CatNet is network scanning software. Use it only against hosts and networks for which you have explicit authorization. Unauthorized scanning may be illegal in your jurisdiction.