# Reporting a security vulnerability

Source: https://codeherder.com/docs/security-reporting/

Report a security flaw in CodeHerder privately, with no account. What to include, the encrypted option, and response times.

Report a security flaw in private. Do not open a public issue. You do not need an account.

## How to report

Email the CodeHerder security contact. The CodeHerder website lists it in its security file, `/.well-known/security.txt`. A self-hosted customer can also use the security contact in its support agreement.

Include:

- what the flaw is and what it lets an attacker do
- the steps to reproduce it
- the version you tested
- any logs or proof-of-concept code

## Send an encrypted report

Send a first email with no details. Ask for a PGP key. We reply with the key. Send the details only after you have it.

## What to expect

- We acknowledge your report within 3 business days.
- We give an initial assessment within 7 business days. It includes a severity rating and next steps.
- We aim to ship a fix or mitigation for a confirmed high-severity issue within 30 days.
- We credit reporters who want credit once the fix ships.

Please give us time to fix the issue before you disclose it.

## On a self-hosted server

Your server answers `GET /.well-known/security.txt` with no token. The file lists the security contact and this policy page.

Two settings change it:

- `CH_SECURITY_CONTACT` sets the contact. Point it at your own security team.
- `CH_SECURITY_POLICY_URL` sets the policy page.

Both are empty by default. With no contact set, the route answers `404`. To report a flaw in CodeHerder itself, always email the CodeHerder security contact above. See [Self-hosted deployment](https://codeherder.com/docs/self-hosting/#report-a-security-flaw).
