We take the security of packageprobe seriously — it is, after all, a security tool. If you believe you have found a vulnerability, we want to hear from you and we will work with you to resolve it.
Reporting a vulnerability
Email security@packageprobe.dev with a description of the issue and steps to reproduce. Please do not open a public issue for security reports. If you would like to encrypt your report, request our PGP key at the same address.
Our machine-readable contact details follow
RFC 9116 and are
published at
/.well-known/security.txt.
Please include, where you can:
- The affected component and version;
- A clear description of the impact;
- Reproduction steps or a proof of concept;
- Any suggested remediation.
Scope
In scope:
- The packageprobe desktop app and CLI;
- The license service, vulnerability proxy, and fleet dashboard;
- The advisory site and this marketing site.
Out of scope:
- Findings that require a compromised host or physical access;
- Reports from automated scanners without a demonstrated impact;
- Social engineering, denial-of-service, and rate-limiting concerns;
- Vulnerabilities in third-party dependencies already tracked upstream (report those upstream, and to us if we are slow to update).
Our commitment
- We will acknowledge your report promptly and keep you updated on progress;
- We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to remediate before public disclosure (safe harbour);
- We will credit you on resolution if you wish.
Coordinated disclosure
We ask that you give us a reasonable window to ship a fix before public disclosure, and that you avoid accessing or modifying other users' data. We will coordinate timing with you.
Response and remediation targets
When you report an issue, we aim to:
- Acknowledge your report within 3 business days;
- Confirm the issue and an initial severity assessment within 10 business days;
- Keep you informed as we work toward a fix, and agree a disclosure date with you.
We triage every finding — whether reported by a researcher or surfaced by our own pre-launch penetration testing — to a severity, and hold ourselves to the following remediation cycle:
- Critical — fixed before the affected component ships; a Critical finding blocks the launch of that component.
- High — fixed before launch; a High finding blocks the launch of that component.
- Medium — triaged with a public target date and fixed within 90 days of triage.
- Low / informational — tracked in our backlog and addressed on a best-effort basis.
Severity follows CVSS v3.1. We may accelerate any of these targets when a finding is being actively exploited.
Bug bounty
We do not run a paid bug-bounty program at launch. We instead operate coordinated disclosure with public credit: report in good faith under the terms above, and — if you wish — we will acknowledge you when the fix ships. We will re-evaluate a paid program after launch once we understand inbound report volume, and this page will be updated either way.
Response targets, remediation timelines, the bug-bounty decision, and the safe-harbour language are a draft pending counsel review.