security vulnerability disclosure
Report a vulnerability.
How to report, what to expect, and what is safe to test.
01
How to report
Email {{ tok.SECURITY_EMAIL }}. PGP key: {{ tok.SECURITY_PGP_FINGERPRINT }}. Include the module version, a reproduction, and impact as you understand it.
02
What to expect
Acknowledgement within {{ tok.DISCLOSURE_ACK_TARGET }}. Status updates every {{ tok.DISCLOSURE_UPDATE_CADENCE }}. Fix or mitigation target: {{ tok.DISCLOSURE_FIX_TARGET }}.
03
In scope
The SpnManager module and C# engine, this website, the evidence-pack signing process.
04
Out of scope
Azure Marketplace and AWS Marketplace platforms (report to them). Your own Active Directory. Denial of service against this website.
05
Safe harbour
{{ tok.SAFE_HARBOUR_TEXT }}
06
Credit
Reporters are credited in the release notes if they wish. {{ tok.BOUNTY_POLICY }}