Security Policy

Git hosting service operated by Vigilis at pawprint.vigilis.online

This policy applies to the git hosting service itself — the Forgejo web application, its API, and the SSH git endpoint on port 2222. It describes how to report a security problem in the service and what you can expect from us in return.

If you found a problem in the content of a repository hosted here (an application, a library, someone's project), please use that project's own security policy where one exists. This page covers the hosting platform itself.

Report security vulnerabilities privately by email to security@vigilis.nl.
Please do not open a public issue and do not disclose publicly until we have had a reasonable opportunity to address the problem.

Reporting a vulnerability

If you would like to encrypt your report, say so in a short first email and we will arrange a key. To help us triage quickly, please include as much of the following as you can:

What to expect from us

We do not run a paid bug-bounty programme; reports are handled on a good-faith basis.

Scope

In scope — the hosting service and everything we operate to run it:

Out of scope:

If you are unsure whether something is in scope, email us and ask before testing.

Rules of engagement (safe harbour)

We support good-faith security research and will not pursue or support legal action against researchers who:

Acting in good faith and within these rules, you should not expect us to treat your research as a violation of our acceptable-use terms.

Supported version

We run a currently supported release of Forgejo and apply security updates as they become available. Security fixes are applied to the running service; there is no support commitment for older, unpatched deployments.

Contact