Security

Report a vulnerability

Send technical details privately so that we can validate the issue and prepare a fix before public disclosure.

Reporting channel not yet available

The project repository is currently private, so there is no external security reporting channel yet. One will be published before the public launch. Do not send vulnerability details through public issues or discussions.

What is in scope

The Fossary website, catalog data, Docker Compose recipes, browser configuration generator, and Compose editor. Report vulnerabilities in an application to its upstream security team unless our recipe or instructions introduce or materially increase the risk.

What to include

  • The affected page, file, recipe, or generated bundle.
  • The conditions and steps needed to reproduce the issue.
  • The expected impact and affected versions.
  • A minimal, non-destructive proof of concept and any suggested mitigation.

Do not send real credentials, personal data, or information taken from systems you do not own or have permission to test.

Coordinated disclosure

Once the channel is available, discussion, validation, and remediation will take place privately. The project has no bug bounty program, but good-faith, non-destructive research is welcome.