Email security@noblerworks.com with enough detail to reproduce: the affected repository, URL, or component, the steps you took, and what you observed. A proof of concept helps. If the issue is sensitive, say so and we will arrange an encrypted channel.
Do not open a public issue for security reports.
Full disclosure policy (response targets, scope, safe harbour): https://noblerworks.com/.well-known/security-policy.txt
- gitgood.dev - security@gitgood.dev (bug bounty: https://gitgood.dev/bug-bounty)
- semantix.chat - security@semantix.chat
Reports about a product sent to security@noblerworks.com will be routed.
- Acknowledgement within 3 business days
- Initial assessment within 10 business days
- Credit offered by default; tell us if you would rather stay anonymous
- No NDA required as a condition of reporting