# Found a security issue? Thank you for telling us first. # # Please report it confidentially to one of the addresses below and give us # reasonable time to ship a fix before you publish anything. We usually reply # within 72 hours and keep you informed until the issue is resolved. Both # addresses reach the same people; security@ is simply the one that says what # the mail is about before anyone opens it. # # Plain email is fine. If you would rather encrypt, the OpenPGP key below # carries the user ID "patchletter UG " — the second # address listed, and the same private key opens mail sent to either one. # Fetch the key straight from this domain, no keyserver involved: # # gpg --locate-keys hello@patchletter.com # # That works because we publish it as a Web Key Directory. Compare the # fingerprint against keys.openpgp.org, where the address is verified: # # D765 266B E43C 0908 47C6 6C38 A3F4 7C85 1471 3E12 Contact: mailto:security@patchletter.com Contact: mailto:hello@patchletter.com Encryption: https://patchletter.com/pgp/hello-at-patchletter.asc Encryption: openpgp4fpr:d765266be43c090847c66c38a3f47c8514713e12 Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en, de Canonical: https://patchletter.com/.well-known/security.txt # A useful report includes: the affected URL, request and response, a rough # timestamp (so we can match it against our logs), and the impact you were # actually able to demonstrate. # # What interests us most: # - access to other people's subscriptions or email addresses # - bypassing the magic-link sign-in or the session handling # - tampering with version or release data — the core of the product: # whoever can lie here keeps admins away from real patches # - anything that lets third parties send mail through our systems # - access to the admin area # # Out of scope: # - scanner output without a demonstrated impact # - missing headers without a concrete attack path # - load or rate-limit tests that degrade the service for others # - social engineering or phishing against operators or users # - real user accounts — create your own account for testing # # patchletter is a free, independent project: no bug bounty, no payouts. # On request we credit you by name in the changelog. We will not take # legal action over good-faith research that stays within these rules.