Skip to content

Security: attify/firmware-analysis-toolkit

SECURITY.md

Security Policy

FAT is a security-research tool. If you discover a vulnerability in FAT itself (not in firmware you are analyzing with it), we appreciate a responsible disclosure.

Reporting a vulnerability

  • Do not open a public GitHub issue for security problems.
  • Use GitHub's private vulnerability reporting ("Report a vulnerability" under the repository's Security tab), or email the maintainers at support@attify.com.
  • Please include a description, affected version/commit, and reproduction steps.

We aim to acknowledge reports within a few business days and will keep you updated on remediation progress.

Scope

This policy covers the FAT codebase in this repository. Findings that FAT produces about third-party firmware are the responsibility of the reporter to disclose to the relevant vendor under that vendor's own policy.

There aren't any published security advisories