Skip to content

Security: ZyxWorks/zyxworks.github.io

SECURITY.md

Reporting a security problem

Do not open a public issue. Use GitHub's private report instead:

the repository's Security tab → Report a vulnerability

That opens a thread only you and we can read. It is on for every repository in this organization, so the same button is there whichever one you found it in.

What to send

Whatever you have. A sentence and a rough reproduction is more useful than nothing, and we would rather read three false alarms than miss one real report.

What happens next

We read it and answer within 7 days. If it is real, we fix it and credit you by name in the release note, unless you would rather stay anonymous. There is no bounty programme — this is a small studio giving tools away, and pretending otherwise would be dishonest.

What is in scope

Anything in this organization's repositories. Our tools run on your own machine and hold no accounts of ours, so the interesting failures are local ones: a file written where it should not be, a permission asked for that is not needed, a shell command built from text somebody else controls.

zyxworks.com is out of scope here — mail the address in its imprint instead.

There aren't any published security advisories