DepWarden takes the security of the service seriously. We welcome reports from security researchers and will work with you to understand and resolve issues quickly. This policy explains what's in scope, how to report, and what you can expect from us in return.
In scope:
Out of scope:
Email [email protected] with the subject line "Security report". Please include a description of the issue and its potential impact, step-by-step reproduction instructions (a proof-of-concept URL, request or script is ideal), and the affected component (web app, API, CLI, Action or Maven plugin).
Our machine-readable contact details are also published at /.well-known/security.txt (RFC 9116).
We aim to acknowledge a new report within 3 business days. We'll work to confirm the issue, assess severity, and give you an honest estimate of remediation timeline once triaged, and keep you updated as the fix progresses. With your permission, we're happy to credit you publicly once the issue is resolved. We don't currently run a paid bug bounty program — recognition is the reward we can offer today.
We consider security research conducted under this policy to be authorized, and won't pursue or support legal action against you for it, provided you report the issue to us privately first and give us a reasonable opportunity to investigate and remediate before any public disclosure; make a good-faith effort to avoid privacy violations, service degradation and destruction of data; only interact with accounts, sessions or data you own or have explicit permission to test; and don't exploit a finding beyond what's necessary to demonstrate it. If in doubt about whether an action is authorized under this policy, ask us first at [email protected] before proceeding.
We ask that you give us up to 90 days from your initial report before any public disclosure, so genuinely complex issues have a realistic window to be fixed. We're happy to discuss a different timeline with you in good faith — most issues we expect to resolve well inside that window.
[email protected]. See also security.txt and our Contact page.