Reporting a security vulnerability
Report a security flaw in CodeHerder privately, with no account. What to include, the encrypted option, and response times.
Report a security flaw in private. Do not open a public issue. You do not need an account.
How to report
Email the CodeHerder security contact. The CodeHerder website lists it in its security file, /.well-known/security.txt. A self-hosted customer can also use the security contact in its support agreement.
Include:
- what the flaw is and what it lets an attacker do
- the steps to reproduce it
- the version you tested
- any logs or proof-of-concept code
Send an encrypted report
Send a first email with no details. Ask for a PGP key. We reply with the key. Send the details only after you have it.
What to expect
- We acknowledge your report within 3 business days.
- We give an initial assessment within 7 business days. It includes a severity rating and next steps.
- We aim to ship a fix or mitigation for a confirmed high-severity issue within 30 days.
- We credit reporters who want credit once the fix ships.
Please give us time to fix the issue before you disclose it.
On a self-hosted server
Your server answers GET /.well-known/security.txt with no token. The file lists the security contact and this policy page.
Two settings change it:
CH_SECURITY_CONTACTsets the contact. Point it at your own security team.CH_SECURITY_POLICY_URLsets the policy page.
Both are empty by default. With no contact set, the route answers 404. To report a flaw in CodeHerder itself, always email the CodeHerder security contact above. See Self-hosted deployment.
Last updated