Only v2 of the Kosli CLI is currently supported! Please try and use the latest release before reporting an issue.
Please send all reports to security@kosli.com and include:
- Clear description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any supporting evidence (screenshots, logs, PoC)
Please report privately by email rather than opening a public issue or pull request, and give us reasonable time to ship a fix before disclosing publicly. This repository is public, so anything raised here is disclosed to everyone at the same moment it reaches us.
There is no bug bounty for the Kosli CLI, and reports against it do not qualify for a payment.
We do run a paid bug bounty for our production platform, app.kosli.com and its supporting APIs, and for www.kosli.com. The scope, testing guidelines, eligibility criteria and bounty rates are published here:
https://www.kosli.com/vulnerability-disclosure
CLI reports are still genuinely welcome, and we would rather hear about a problem than not. We will acknowledge your report, assess it, tell you our determination and reasoning, fix what needs fixing, and credit you in the release notes if you would like us to.
Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we're committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we'll explain our reasoning.