Skip to content

Security: Inkloom-art/inkloom

Security

SECURITY.md

Reporting a vulnerability

Please report it privately. Do not open a public issue, and do not post details anywhere public until it is fixed.

Two ways, either is fine:

What to include

Whatever you have. A short description and the steps to reproduce is enough; a proof of concept is welcome but not required. If you are unsure whether something is a vulnerability, report it anyway — a false alarm costs us a few minutes, and an unreported issue costs a great deal more.

What to expect

Acknowledgement within 3 working days
First assessment within 7 working days
Fix or a dated plan within 30 days for anything we rate high or critical

We will tell you what we found, what we changed, and when it shipped. If we decide something is not a vulnerability we will say why rather than go quiet.

Scope

In scope: inkloom.art, the API beneath it, and this repository.

Out of scope, because they are not ours to fix: Cloudflare, Neon, Resend and GitHub themselves — report those to the vendor. Also out of scope: reports generated by a scanner with no demonstrated impact, missing headers with no exploit path, and anything requiring physical access to a user's unlocked device.

What we ask

Stay inside your own account. Do not access, modify or delete anyone else's data. Do not run denial-of-service tests, automated scanning that degrades the service, or social engineering against anyone. Give us reasonable time to fix an issue before disclosing it.

Do that, and we will treat your report as good-faith research and will not pursue action over it.

Credit

We are glad to name you in the advisory and the release notes if you would like that, and equally glad not to. Tell us which.

Before you start

Some things are known and deliberate rather than undiscovered — generation and payments are not built, and the flags that would enable them default to off. If a report depends on a feature that does not exist yet, say so and we will tell you where it stands.

There is no paid bounty programme at this stage. We would rather say so plainly than imply one.

There aren't any published security advisories