gitGost takes security seriously, particularly given its focus on privacy and anonymity. We welcome responsible vulnerability reports to maintain trust with our users.
We accept vulnerability reports responsibly. To protect your anonymity, we provide multiple channels:
To report a security issue, please open a security advisory on GitHub with a detailed description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue.
- Clear description of the vulnerability.
- Steps to reproduce it.
- Potential impact.
- Suggested mitigations (optional).
- Acknowledgment of receipt within 7 business days.
- Status updates every 7-14 days.
- Resolution of critical vulnerabilities within 30 days.
- Do not create public issues for unconfirmed vulnerabilities.
- Avoid discussing exploit details in public.
- Do not use issues for general security inquiries.
- No legal action will be taken against good-faith reports.
- Anonymous reports may receive credit if requested (optional).
- We adhere to standards such as Responsible Disclosure.
If you have questions, contact us anonymously.
We prefer all communications to be in Spanish.
Thank you for helping keep gitGost secure.