Vulnerability Disclosure Policy

DepWarden takes the security of the service seriously. We welcome reports from security researchers and will work with you to understand and resolve issues quickly. This policy explains what's in scope, how to report, and what you can expect from us in return.

1. Scope

In scope:

Out of scope:

2. How to report

Email [email protected] with the subject line "Security report". Please include a description of the issue and its potential impact, step-by-step reproduction instructions (a proof-of-concept URL, request or script is ideal), and the affected component (web app, API, CLI, Action or Maven plugin).

Our machine-readable contact details are also published at /.well-known/security.txt (RFC 9116).

3. What to expect from us

We aim to acknowledge a new report within 3 business days. We'll work to confirm the issue, assess severity, and give you an honest estimate of remediation timeline once triaged, and keep you updated as the fix progresses. With your permission, we're happy to credit you publicly once the issue is resolved. We don't currently run a paid bug bounty program — recognition is the reward we can offer today.

4. Safe harbor

We consider security research conducted under this policy to be authorized, and won't pursue or support legal action against you for it, provided you report the issue to us privately first and give us a reasonable opportunity to investigate and remediate before any public disclosure; make a good-faith effort to avoid privacy violations, service degradation and destruction of data; only interact with accounts, sessions or data you own or have explicit permission to test; and don't exploit a finding beyond what's necessary to demonstrate it. If in doubt about whether an action is authorized under this policy, ask us first at [email protected] before proceeding.

5. Coordinated disclosure

We ask that you give us up to 90 days from your initial report before any public disclosure, so genuinely complex issues have a realistic window to be fixed. We're happy to discuss a different timeline with you in good faith — most issues we expect to resolve well inside that window.

6. Contact

[email protected]. See also security.txt and our Contact page.