generated: '2026-09-06' method: searched probe: true source: https://github.com/apiman/apiman/blob/master/SECURITY.md policy: - https://github.com/apiman/apiman/blob/master/SECURITY.md - https://github.com/apiman/apiman/security/advisories/new contact: - marc@blackparrotlabs.io intake: preferred: GitHub private vulnerability reporting ("Report a Vulnerability") url: https://github.com/apiman/apiman/security/advisories/new alternate_email: marc@blackparrotlabs.io alternate_contact_profile: https://github.com/msavy bug_bounty: offered: false platform: null supported_versions: supported: ['3.x'] unsupported: ['2.x', '1.x'] note: Downstream support-provider users are told to contact their vendor for supported versions. security_txt: served: false note: >- /.well-known/security.txt returns 404 on both www.apiman.io and apiman.io; the site's 404 page is 10,151 bytes of HTML and a negative-control path also 404s, so this is a real absence rather than a catch-all. Publishing an RFC 9116 security.txt on www.apiman.io pointing at SECURITY.md would be a one-file improvement. disclosure_history: - id: CVE-2023-28640 title: Potential permissions bypass in Apiman 3.0.0.Final published: '2023-03-27' url: https://www.apiman.io/blog/potential-permissions-bypass-disclosure/ - title: Potential permissions bypass in Apiman 1.5.7 through 2.2.3.Final published: '2022-12-19' url: https://www.apiman.io/blog/potential-permissions-bypass-disclosure/ note: >- Both advisories were published on the project blog as well as through GitHub, which is evidence of an actually-exercised disclosure process rather than a policy file alone. evidence: - source: https://github.com/apiman/apiman/blob/master/SECURITY.md kind: security-policy http_status: 200 - source: https://www.apiman.io/.well-known/security.txt kind: security.txt http_status: 404 - source: blogs/2023-03-27-potential-permissions-bypass-in-apiman-3-0-0-final-cve-2023-28640.md kind: advisory