Vulnerability Disclosure & Security Policy¶
We are committed to resolving security vulnerabilities quickly and responsibly to protect users and infrastructure.
1. Reporting a Vulnerability¶
If you discover a security issue or potential vulnerability in StackPilot:
- Email: Send detailed findings to
security@stackpilot.local(or create a private GitHub Security Advisory). - Public Disclosure: Please do not open public GitHub issues or discuss undisclosed vulnerabilities on social media or forums until a fix has been coordinated and released.
2. Report Guidelines¶
To help us triage and remediate the issue rapidly, please include:
- Affected Components: Specify whether the issue affects the Central Hub, Agent ZipApp, or Installer script.
- Impact Assessment: Explain what an attacker could achieve (e.g., privilege escalation, unauthorized state modification, sensitive information leak).
- Reproduction Steps: Detailed instructions, curl commands, or a minimal Proof-of-Concept (PoC).
- Environment Details: Linux distribution, Podman/Docker version, and StackPilot version.
3. SLA & Response Timeline¶
| Phase | Target Timeline |
|---|---|
| Initial Acknowledgment | Within 48 hours |
| Triage & Severity Rating | Within 5 business days |
| Mitigation & Patch Release | Coordinated with reporter (typically 14 to 30 days) |
Security releases are published with clear release notes and CVE attribution when applicable.