Vulnerability Disclosure
Vulnpatch is a vulnerability intelligence service, so a working disclosure path is part of the product rather than a formality. This page is the policy that every host's /.well-known/security.txt points at. It says what is in scope, what a researcher may do, how to report and what Vulnpatch commits to in return. The same text is published at cve.vulnpatch.dev/security.
Scope
In scope:
vulnpatch.devcve.vulnpatch.devapi.vulnpatch.devdocs.vulnpatch.dev- the published nixpkgs OSV feed at
/api/v1/feed/osv/nixpkgs
Out of scope, with where the report belongs instead:
| Finding | Where it goes |
|---|---|
| A vulnerability in a third-party package or a CVE's own content | The project's maintainers, or the CNA that owns the CVE |
| An incorrect record in the data Vulnpatch relays (a mapping, a fix date, a severity) | The data corrections path; it is not a vulnerability report |
| A flaw in an upstream data source (CVE Program, NVD, CISA, GitHub, OSV, FIRST, Repology) | That source |
| A platform issue in Cloudflare or GitHub | That platform |
| Denial of service, rate-limit exhaustion or volume as a finding | Not accepted |
| Social engineering, or findings that need physical access | Not accepted |
| Output of an automated scanner with no demonstrated impact | Not accepted |
Other Ad Astra Computing services are outside this policy's scope but are reported to the same address.
Safe harbour
Security research is considered authorised when it makes a good-faith effort to comply with this policy. For inadvertent, good-faith violations of this policy, Ad Astra Computing will not take civil action or file a report with law enforcement.
Good faith means:
- stop at demonstration; do not exploit a finding further than is needed to show it exists
- do not access, modify or retain other people's data; if you reach it, stop and report it
- do not degrade the service for other users
- give Vulnpatch the time this page commits to before publishing
How to report
Email security@adastracomputing.com. Anonymous reports are accepted, and no personal data is required to make one. Say which host, what you found, how to reproduce it and what you believe the impact is. A proof of concept helps; a full exploit is not needed.
There is no encrypted reporting channel at present, so do not send material that would need one; describe it and Vulnpatch will arrange a channel.
What Vulnpatch commits to
| Step | Commitment |
|---|---|
| Acknowledgement | Within 5 business days of receipt |
| Initial assessment | Within 10 business days: whether the report is accepted, its severity and what happens next |
| Fix or mitigation | Target of 90 days from acknowledgement |
| Progress | A status update at least every 30 days while the report is open |
| Credit | With the reporter's consent, once the fix ships |
Vulnpatch is operated by a small team. Five business days is what can be kept, so it is what is promised.
There is no bug bounty. Reports are welcome and credited; they are not paid.
Disclosure
Disclosure is coordinated. Once the fix ships, or 90 days after acknowledgement, whichever comes first, the reporter may publish. Vulnpatch publishes a short note of its own at the same time. If a fix will take longer than 90 days, Vulnpatch will say so before the deadline and propose a date rather than let it pass in silence.
Machine-readable
Each host publishes an RFC 9116 security.txt naming this page as its policy: