BOFA is intended for authorized security research, defensive operations and education. Do not use it against systems without explicit permission.
Security fixes target the latest tagged release and the current main branch.
Older releases may not receive backports.
Do not open a public issue with exploit details, credentials or sensitive evidence.
Send the report to david@descambiado.com with:
- Affected version or commit.
- Impact and realistic attack scenario.
- Minimal reproduction steps.
- Suggested remediation, when available.
You may attach a report generated by BOFA, but remove secrets, tokens and third-party data first. We aim to acknowledge a report within seven days and coordinate disclosure after a fix or mitigation is available.
Reports about BOFA's API, authentication, execution runtime, evidence bundles, dependency chain, Docker labs and frontend are in scope. Vulnerabilities found in third-party targets while using BOFA must be reported to the relevant program or vendor instead.
- Test only systems you own or are explicitly authorized to assess.
- Prefer non-destructive checks and respect program rate limits.
- Never commit live credentials or private target evidence to this repository.
- Follow local law and the disclosure policy of the affected program.