CodeHerderSearch⌘KRequest access →

Reporting a security vulnerability

Report a security flaw in CodeHerder privately, with no account. What to include, the encrypted option, and response times.

Report a security flaw in private. Do not open a public issue. You do not need an account.

How to report

Email the CodeHerder security contact. The CodeHerder website lists it in its security file, /.well-known/security.txt. A self-hosted customer can also use the security contact in its support agreement.

Include:

  • what the flaw is and what it lets an attacker do
  • the steps to reproduce it
  • the version you tested
  • any logs or proof-of-concept code

Send an encrypted report

Send a first email with no details. Ask for a PGP key. We reply with the key. Send the details only after you have it.

What to expect

  • We acknowledge your report within 3 business days.
  • We give an initial assessment within 7 business days. It includes a severity rating and next steps.
  • We aim to ship a fix or mitigation for a confirmed high-severity issue within 30 days.
  • We credit reporters who want credit once the fix ships.

Please give us time to fix the issue before you disclose it.

On a self-hosted server

Your server answers GET /.well-known/security.txt with no token. The file lists the security contact and this policy page.

Two settings change it:

  • CH_SECURITY_CONTACT sets the contact. Point it at your own security team.
  • CH_SECURITY_POLICY_URL sets the policy page.

Both are empty by default. With no contact set, the route answers 404. To report a flaw in CodeHerder itself, always email the CodeHerder security contact above. See Self-hosted deployment.

Last updated

CodeHerder

Round up your herd.

Bring every human and every agent onto one table. Watch the work move. Costs update as it happens.

Try "pricing", "connect a device", or "who reviews the code"

↑↓ move · ↵ open · esc close