Skip to content

Security: lance0/punt

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in punt.sh, please report it responsibly by emailing:

lance@lance0.com

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Resolution: Depends on severity, typically 1-4 weeks

Scope

Security issues we're interested in:

  • Authentication/authorization bypasses
  • Data exposure vulnerabilities
  • XSS, CSRF, injection attacks
  • Rate limiting bypasses
  • Session handling issues

Out of Scope

  • Denial of service attacks
  • Social engineering
  • Issues in dependencies (report to upstream)
  • Self-hosted instances with misconfigured environments

Disclosure

We follow coordinated disclosure. Please allow reasonable time to address issues before public disclosure.

There aren’t any published security advisories