Security reporting

Report a Uleravo vulnerability privately.

If you find a vulnerability in the Uleravo CLI, GitHub Action, download, or website, contact us privately before publishing details.

Last updated September 2, 2026

Contact

Email s.aloufi01@gmail.com with “Private Uleravo security report” in the subject. We will acknowledge a complete report within five business days.

The pilot aims to respond to product support requests within two business days. Security reports follow the schedule above.

Include the affected version or URL, impact, minimal reproduction steps, and any suggested fix. Do not send live credentials, customer data, or unnecessary source.

Research boundaries

  • Test only systems and data you own or are authorized to assess.
  • Avoid denial of service, social engineering, persistence, privacy violations, and destructive testing.
  • Stop and report if you encounter data that is not yours.
  • Allow reasonable time for investigation and remediation before public disclosure.

Scanner reports

Reports can contain sensitive paths and redacted evidence. Before sharing a false positive or missed detection, reduce it to the smallest synthetic example possible and follow the guidance above.

Uleravo performs static analysis; it does not certify that a repository is secure. A complete scan means only that Uleravo processed every accepted input within the documented analyzer scope.