Security reports are welcome for active, source repositories owned by @foobarto. A repository-specific security policy takes precedence over this account-wide fallback.
Forks and archived repositories are not maintained and are outside this policy. Third-party services, dependencies, and infrastructure should be reported to their respective owners unless the vulnerability is caused by how a foobarto project integrates with them.
Do not disclose vulnerabilities in a public issue, discussion, or pull request.
Preferred: open the affected repository's Security tab, select Report a vulnerability, and submit a private report. This keeps the report confidential and scoped to the correct project.
Fallback: if private vulnerability reporting is unavailable, email
bartosz@foobarto.me. PGP is strongly preferred for sensitive material:
- fingerprint:
F858 BE96 A0D1 E6FD CAF7 C4D6 06FD 46A0 2874 AF8D; - public key: https://foobarto.me/.well-known/openpgpkey/foobarto.me.asc;
- machine-readable contact: https://foobarto.me/.well-known/security.txt.
Include the affected repository and version or commit, a numbered reproduction that ends in observable impact, relevant environment details, and any useful logs or proof of concept. Remove credentials, personal data, and third-party confidential material.
Reports are normally acknowledged within 72 hours. Confirmed issues follow a 90-day coordinated-disclosure default, or earlier disclosure after a fix ships. Status, support, and remediation depend on the affected project's maintenance state and any repository-specific policy.
Good-faith research should demonstrate impact and then stop: do not access data that is not yours, pivot beyond the affected project, disrupt services, or publish before coordinated disclosure. The full rules of engagement and safe harbor statement are at https://foobarto.me/security/.