Ploydok is pre-release (< 1.0). Only the main branch receives security fixes.
Do not open a public issue for security vulnerabilities.
Email: security@ploydok.dev
PGP key: TODO — publish before v1.0
- Description of the vulnerability and affected component
- Reproduction steps (minimal PoC preferred)
- Impact assessment
- Your disclosure timeline expectations
- Acknowledgement within 72 hours
- Triage and severity assessment within 7 days
- Fix timeline communicated after triage (depending on severity)
- Credit in advisory if desired
In scope
- Ploydok source code (this repository)
- Official Docker images and install scripts published by the project
- Official CLI and agent binaries
Out of scope
- User deployments or self-hosted instances misconfigured by operators
- Third-party dependencies (report upstream first, copy us)
- Social engineering, physical attacks, DoS
- Issues requiring root on the host to exploit