Skip to content

Vulnerability Disclosure & Security Policy

We are committed to resolving security vulnerabilities quickly and responsibly to protect users and infrastructure.


1. Reporting a Vulnerability

If you discover a security issue or potential vulnerability in StackPilot:

  • Email: Send detailed findings to security@stackpilot.local (or create a private GitHub Security Advisory).
  • Public Disclosure: Please do not open public GitHub issues or discuss undisclosed vulnerabilities on social media or forums until a fix has been coordinated and released.

2. Report Guidelines

To help us triage and remediate the issue rapidly, please include:

  1. Affected Components: Specify whether the issue affects the Central Hub, Agent ZipApp, or Installer script.
  2. Impact Assessment: Explain what an attacker could achieve (e.g., privilege escalation, unauthorized state modification, sensitive information leak).
  3. Reproduction Steps: Detailed instructions, curl commands, or a minimal Proof-of-Concept (PoC).
  4. Environment Details: Linux distribution, Podman/Docker version, and StackPilot version.

3. SLA & Response Timeline

Phase Target Timeline
Initial Acknowledgment Within 48 hours
Triage & Severity Rating Within 5 business days
Mitigation & Patch Release Coordinated with reporter (typically 14 to 30 days)

Security releases are published with clear release notes and CVE attribution when applicable.