ravage

Security Policy

Ravage is a pre-1.0 research project for controlled, authorized security testing. Its lab applications are intentionally vulnerable; the security policy covers Ravage itself, its packaging, and the boundaries it promises to enforce.

Supported Versions

Security fixes target the latest commit on main and the latest tagged release, when one exists. Older releases, superseded snapshots, historical benchmark archives, and intentionally vulnerable lab targets are not supported release lines.

The legacy 0.0.1 PyPI packages should not be treated as the current source release. Until a newer tagged release is published, use the repository checkout and identify the exact commit in reports.

Report A Vulnerability Privately

Use GitHub private vulnerability reporting.

Do not disclose security details in a public issue, pull request, discussion, benchmark artifact, or log. Do not include provider keys, cookies, customer data, real credentials, or unredacted target evidence.

Include only what is needed to reproduce the problem:

Please coordinate disclosure until a fix or mutually agreed disclosure date is available. Response and remediation timing is best effort; this is currently a small research project without a paid security-response program.

In Scope

Examples include:

Out Of Scope

Use a normal issue or the benchmark-reproduction template for:

Testing Boundaries

Test Ravage only against local synthetic fixtures, isolated lab boxes, or systems you own and are explicitly authorized to assess. This policy does not authorize testing third-party infrastructure, maintainer accounts, package registries, or model providers.

Do not perform denial-of-service testing, social engineering, credential attacks, or destructive testing. There is currently no bug-bounty or payment program.