security

Security

keygrant handles other people’s credentials, so we take reports seriously and would much rather hear about a problem than have it stay hidden.

Reporting a vulnerability

Please report privately through GitHub’s private vulnerability reporting rather than a public issue. Include what you found, how to reproduce it, and what you think the impact is. We’ll acknowledge it, keep you updated, and credit you in the fix unless you’d rather not be named.

If that form isn’t available to you, open a regular issue that only says you have a security report and asks for a private channel. Please leave the details out of it.

In scope

Known limits, not vulnerabilities

These are documented in the threat model:

New ways around these are still welcome as reports: for example, an encoding we should add.