Security
Security and responsible disclosure
How to report a vulnerability in Talarurus software or on this website.
Reporting a vulnerability
If you believe you have found a security vulnerability in Hammerhead, another Talarurus project, or talarurus.com, please report it privately by email to [email protected].
Good-faith reports are welcome. Please do not disclose a suspected vulnerability publicly, including in a public GitHub issue, until it has been addressed.
Scope
- Hammerhead and other software published by Talarurus.
- The talarurus.com website.
Issues in third-party services, such as GitHub or Cloudflare, should be reported to those providers directly.
What to include
A useful report usually contains:
- The affected project and version (for example, Hammerhead v0.1.0) or the affected URL.
- A description of the issue and its potential impact.
- Steps to reproduce it, and a minimal proof of concept where possible.
- Relevant details of your environment, such as operating system and how the software was run.
- Whether the issue is already publicly known.
- Whether, and how, you would like to be credited.
Testing guidelines
When researching a potential issue, please:
- Do not perform destructive testing, or anything that could degrade or disrupt the website or other services.
- Do not run denial-of-service tests or high-volume automated scans against talarurus.com.
- Do not access, modify, or delete data that does not belong to you.
- Do not violate the privacy of others. If you encounter someone else's data, stop and include that in your report.
- Do not use social engineering, phishing, or physical attacks.
- Test Talarurus software in an environment you own and control.
What to expect
Talarurus reviews good-faith security reports and aims to acknowledge them. We may ask follow-up questions while an issue is investigated. Please allow reasonable time for a fix before any public disclosure; we are open to coordinating disclosure timing with you.
Other notes
- Talarurus does not currently run a paid bug bounty program.
- No PGP key is published at this time. If your report includes sensitive details, send a short initial email without them so a suitable way to share them can be discussed.
- This page is guidance for reporting security issues. It is not a contract and does not grant authorization beyond what is described here.