Skip to content

Security: legioncodeinc/macsitna

Security

SECURITY.md

Security Policy

MACSITNA is a public anti-scam operation run by Legion Code Inc. This policy covers the macsitna.com website and this repository.

Supported Versions

MACSITNA is a continuously deployed website, not a versioned library. There are no supported historical releases: the only supported version is whatever is currently live at https://macsitna.com, built from the tip of the main branch.

What Supported
Current deployment of macsitna.com (main)
Preview deployments ✅ (report these too)
Any earlier commit or tag

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities through GitHub private vulnerability reporting for this repository. That channel is private to the maintainers and lets us coordinate a fix and an advisory in one place.

If private vulnerability reporting is unavailable to you, open a public issue that contains only a request for a private channel: no details, no proof of concept, no affected URL. A maintainer will open a private advisory and invite you to it.

When reporting, please include:

  • The affected URL, commit SHA, or deployment
  • A description of the issue and why you believe it is security-sensitive
  • Steps to reproduce, or a proof of concept
  • Any relevant logs, payloads, or screenshots
  • The potential impact
  • Any suggested mitigations or fixes, if known

What to Expect

You can expect an acknowledgment within 3 business days.

After acknowledgment, we will assess the report and follow up with next steps. If the issue is confirmed, we will work on a fix and coordinate disclosure timing with you. We will credit reporters in the resulting GitHub Security Advisory unless you ask us not to.

Scope

In scope:

  • This repository and its build, CI, and deployment configuration
  • The macsitna.com website and its preview deployments
  • The Payload CMS admin surface and its API
  • Anything that exposes reader data, submitted reports, or maintainer credentials

Out of scope:

  • Findings that require physical access to a maintainer's device
  • Social engineering of maintainers or Legion Code Inc. staff
  • Automated scanner output with no demonstrated impact
  • Volumetric denial of service
  • Missing security headers or best-practice deviations with no demonstrated exploit path (open these as normal issues instead)

A note on the subject matter

MACSITNA publishes material about active scam operations. If you believe a page on this site exposes something that puts a victim, researcher, or source at risk, treat that as a security report and use the private channel above, even though it is not a software vulnerability.

There aren't any published security advisories