We take the security of pkgprobe seriously — it is, after all, a security tool. If you believe you have found a vulnerability, we want to hear from you and we will work with you to resolve it.
Reporting a vulnerability
Email security@pkgprobe.dev with a description of the issue and steps to reproduce. Please do not open a public issue for security reports. If you would like to encrypt your report, request our PGP key at the same address.
Please include, where you can:
- The affected component and version;
- A clear description of the impact;
- Reproduction steps or a proof of concept;
- Any suggested remediation.
Scope
In scope:
- The pkgprobe desktop app and CLI;
- The license service, vulnerability proxy, and fleet dashboard;
- The advisory site and this marketing site.
Out of scope:
- Findings that require a compromised host or physical access;
- Reports from automated scanners without a demonstrated impact;
- Social engineering, denial-of-service, and rate-limiting concerns;
- Vulnerabilities in third-party dependencies already tracked upstream (report those upstream, and to us if we are slow to update).
Our commitment
- We will acknowledge your report promptly and keep you updated on progress;
- We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to remediate before public disclosure (safe harbour);
- We will credit you on resolution if you wish.
Coordinated disclosure
We ask that you give us a reasonable window to ship a fix before public disclosure, and that you avoid accessing or modifying other users' data. We will coordinate timing with you.
Response targets, any bug-bounty terms, and the safe-harbour language are a draft pending counsel review.