Email security@macula.io. Please do not open a public issue for anything that could be exploited against the running Macula fleet (the stations, the realm or the services on it).
Tell us, as far as you can:
- the repository, and the release or commit you looked at;
- what you found and how to reproduce it;
- what an attacker could do with it.
Plain email is fine; there is no encryption key to use.
- Exploitable on the running fleet: kept private until it is fixed, then published as an advisory.
- Hardening findings (a weakness nothing can exploit today): filed as a public issue, written in defensive terms: the invariant, the limit, the fix and the test.
We confirm that we received your report, tell you which of the two it is, and keep you informed until it is closed. We credit you in the advisory or the issue unless you ask us not to.
This policy covers this repository and the rest of Macula: the SDKs, the relay stations, the realm, the mcl-* services and the fleet they run on. The fleet is a development fleet; please ask before running load or denial-of-service tests against it. A vulnerability in a third-party dependency belongs with its maintainers; tell us too if it affects Macula.