Skip to content

Security policy

Do not disclose a suspected vulnerability, credential, exploit, customer payload, private topology, or other sensitive evidence in a public GitHub issue or discussion.

Email oss@cratis.io with Security: at the start of the subject. Include only the information needed to route and reproduce the report:

  • affected Cratis repository, package, image, and exact version or commit;
  • the behavior you observed and the behavior you expected;
  • bounded reproduction steps or a minimal reproducer;
  • the conditions required to reach the behavior;
  • the potential impact as you understand it; and
  • a safe way to contact you for follow-up.

Do not place credentials, customer data, personal data, production data, or sensitive logs in the first message. Ask for an appropriate private transfer method when additional evidence is necessary.

Use the affected repository’s public issue tracker for ordinary defects and feature requests that contain no sensitive security information. A public issue, pull request, build, release, or package does not establish that a product is secure, compliant, supported, or suitable for a particular environment.

This policy provides a private reporting route. It does not create a response-time commitment, service-level agreement, warranty, support plan, disclosure deadline, bounty, or statement about the security posture of any Cratis product. Applicable licenses and separately accepted agreements retain their own terms.