security
Report a vulnerability.
Reports are accepted for every public repository under github.com/ScriptKittyOS and for this site. They are acknowledged, fixed in the open where the fix does not itself create exposure, and credited if you want credit.
How to report.
- A repository. Open the repository on GitHub, go to its Security tab, and choose "Report a vulnerability". The report stays private between you and the maintainers until a fix is published.
- This site, or anything without a repository. Use the contact form with the topic "Security report", and say only that it is one. A private channel is set up in reply. Do not put vulnerability details in the first message.
- What to include once the channel is private: the repository and commit or the page URL, steps to reproduce, the impact you observed, and whether you want credit.
- What not to include: other people's data, credentials, or anything obtained by exceeding the minimum needed to demonstrate the issue.
Scope.
In scope: the public repositories Trinity, beam_mcp, beam_mcp_signer, HolyTrinity-Benchmark and Requisition-Benchmark, Ultraviolet once it is published, and scriptkittyos.com.
Out of scope until the arena opens: any production instance of Sanction OS or Requisition. The arena is the sanctioned surface for attacking Requisition; it does not exist yet.
Safe harbor.
When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be:
- Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
- Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
- Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and
- Lawful, helpful to the overall security of the Internet, and conducted in good faith.
You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.
Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties.
The safe harbor text above is the disclose.io safe harbor term (dioterms, CC0-1.0), quoted unchanged. "Official Channels" are the two in "How to report" above.
What to expect.
- Acknowledgement of receipt.
- A fix, or a documented decision not to fix with the reason.
- Credit in the release notes if you ask for it.
- No reward. A reward framework is in draft and will be published before any paid program exists.
Machine-readable contact details: /.well-known/security.txt.