Documentation menu
On this page

Security policy

WardenClaw is an execution gate: a way around the gate is the most important bug you can find. Thank you for reporting it privately.

How to report

Please do not open a public issue, discussion or pull request for a vulnerability.

Write to valiullin.arthur@gmail.com. GitHub private vulnerability reporting opens together with the code, with the first release.

Please include what you found, the affected version or commit, how to reproduce it and the impact you expect. A proof of concept helps a lot.

Encryption

There is no PGP key for reports yet. By email, send the description and the impact first, without a working exploit, and we agree on a private way to pass the details.

Response times

WardenClaw is pre-1.0. Security fixes go to the main branch and the latest release only.

Scope

In scope:

Out of scope:

Release signatures

Every release is signed with an offline minisign key. The key, where else it is published and what to do when it does not match: Verify releases.

The same contacts in machine-readable form (RFC 9116): /.well-known/security.txt.