Skip to content

Security: dev-toolings/ploydok

Security

SECURITY.md

Security Policy

Supported versions

Ploydok is pre-release (< 1.0). Only the main branch receives security fixes.

Reporting a vulnerability

Do not open a public issue for security vulnerabilities.

Email: security@ploydok.dev

PGP key: TODO — publish before v1.0

What to include

  • Description of the vulnerability and affected component
  • Reproduction steps (minimal PoC preferred)
  • Impact assessment
  • Your disclosure timeline expectations

Our commitments

  • Acknowledgement within 72 hours
  • Triage and severity assessment within 7 days
  • Fix timeline communicated after triage (depending on severity)
  • Credit in advisory if desired

Scope

In scope

  • Ploydok source code (this repository)
  • Official Docker images and install scripts published by the project
  • Official CLI and agent binaries

Out of scope

  • User deployments or self-hosted instances misconfigured by operators
  • Third-party dependencies (report upstream first, copy us)
  • Social engineering, physical attacks, DoS
  • Issues requiring root on the host to exploit

There aren't any published security advisories