Commit 8f9dc157d2
Unsigned
Layout: unified · split
SECURITY.md added +55
| @@ -0,0 +1,55 @@ | ||
| 1 | # Security Policy | |
| 2 | ||
| 3 | ## Supported versions | |
| 4 | ||
| 5 | gh-attest is a hosted GitHub App. There is one supported version — the | |
| 6 | currently deployed one. Fixes are rolled out to all installations at once; | |
| 7 | there is nothing for you to upgrade. | |
| 8 | ||
| 9 | ## Reporting a vulnerability | |
| 10 | ||
| 11 | Please report privately rather than opening a public issue. | |
| 12 | ||
| 13 | - **Preferred:** [Report a vulnerability](https://github.com/audit-labs/gh-attest/security/advisories/new) | |
| 14 | via GitHub private vulnerability reporting. | |
| 15 | - **Alternative:** email `security@audit-labs.dev`. | |
| 16 | ||
| 17 | Please include enough detail to reproduce: the endpoint or component, the | |
| 18 | request, and what you observed. If you have a proof of concept, use your own | |
| 19 | organization's installation. | |
| 20 | ||
| 21 | We aim to acknowledge within 3 working days and to keep you updated until the | |
| 22 | issue is resolved. We will credit you when publishing a fix unless you prefer | |
| 23 | otherwise. We do not currently run a paid bug bounty. | |
| 24 | ||
| 25 | ## Scope | |
| 26 | ||
| 27 | **In scope** | |
| 28 | ||
| 29 | - The Worker and its endpoints, including webhook signature verification, | |
| 30 | session handling, and the `/admin/*` bearer-guarded routes. | |
| 31 | - Tenant isolation — anything allowing one installation to read another's | |
| 32 | evidence or exports. | |
| 33 | - The evidence pipeline, where incorrect data could mislead an audit. | |
| 34 | ||
| 35 | **Out of scope** | |
| 36 | ||
| 37 | - GitHub and Cloudflare themselves. Report those to | |
| 38 | [GitHub](https://bounty.github.com/) and | |
| 39 | [Cloudflare](https://hackerone.com/cloudflare) respectively. | |
| 40 | - Findings that gh-attest *reports about your own organization* — a repository | |
| 41 | without branch protection is the product working, not a vulnerability. | |
| 42 | - Denial of service, volumetric testing, and social engineering. | |
| 43 | ||
| 44 | ## Testing guidance | |
| 45 | ||
| 46 | Please test against an installation on an organization you control. Do not | |
| 47 | attempt to access data belonging to another installation; if you believe you | |
| 48 | have found a way to, stop and report it rather than confirming the extent. | |
| 49 | ||
| 50 | ## How gh-attest handles data | |
| 51 | ||
| 52 | Read-only GitHub scopes, short-lived installation tokens that are never | |
| 53 | persisted, no source code or personal access tokens stored, and all data held | |
| 54 | in the EU. See [PRIVACY.md](PRIVACY.md) for the full description and | |
| 55 | [README.md](README.md) for the architecture. | |