Skip to content

Vulnerability Disclosure ​

Vulnpatch is a vulnerability intelligence service, so a working disclosure path is part of the product rather than a formality. This page is the policy that every host's /.well-known/security.txt points at. It says what is in scope, what a researcher may do, how to report and what Vulnpatch commits to in return. The same text is published at cve.vulnpatch.dev/security.

Scope ​

In scope:

  • vulnpatch.dev
  • cve.vulnpatch.dev
  • api.vulnpatch.dev
  • docs.vulnpatch.dev
  • the published nixpkgs OSV feed at /api/v1/feed/osv/nixpkgs

Out of scope, with where the report belongs instead:

FindingWhere it goes
A vulnerability in a third-party package or a CVE's own contentThe project's maintainers, or the CNA that owns the CVE
An incorrect record in the data Vulnpatch relays (a mapping, a fix date, a severity)The data corrections path; it is not a vulnerability report
A flaw in an upstream data source (CVE Program, NVD, CISA, GitHub, OSV, FIRST, Repology)That source
A platform issue in Cloudflare or GitHubThat platform
Denial of service, rate-limit exhaustion or volume as a findingNot accepted
Social engineering, or findings that need physical accessNot accepted
Output of an automated scanner with no demonstrated impactNot accepted

Other Ad Astra Computing services are outside this policy's scope but are reported to the same address.

Safe harbour ​

Security research is considered authorised when it makes a good-faith effort to comply with this policy. For inadvertent, good-faith violations of this policy, Ad Astra Computing will not take civil action or file a report with law enforcement.

Good faith means:

  • stop at demonstration; do not exploit a finding further than is needed to show it exists
  • do not access, modify or retain other people's data; if you reach it, stop and report it
  • do not degrade the service for other users
  • give Vulnpatch the time this page commits to before publishing

How to report ​

Email security@adastracomputing.com. Anonymous reports are accepted, and no personal data is required to make one. Say which host, what you found, how to reproduce it and what you believe the impact is. A proof of concept helps; a full exploit is not needed.

There is no encrypted reporting channel at present, so do not send material that would need one; describe it and Vulnpatch will arrange a channel.

What Vulnpatch commits to ​

StepCommitment
AcknowledgementWithin 5 business days of receipt
Initial assessmentWithin 10 business days: whether the report is accepted, its severity and what happens next
Fix or mitigationTarget of 90 days from acknowledgement
ProgressA status update at least every 30 days while the report is open
CreditWith the reporter's consent, once the fix ships

Vulnpatch is operated by a small team. Five business days is what can be kept, so it is what is promised.

There is no bug bounty. Reports are welcome and credited; they are not paid.

Disclosure ​

Disclosure is coordinated. Once the fix ships, or 90 days after acknowledgement, whichever comes first, the reporter may publish. Vulnpatch publishes a short note of its own at the same time. If a fix will take longer than 90 days, Vulnpatch will say so before the deadline and propose a date rather than let it pass in silence.

Machine-readable ​

Each host publishes an RFC 9116 security.txt naming this page as its policy: