Skip to content

Security: neonwatty/bugdrop

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Email security concerns to: neonwatty@gmail.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix timeline: Depends on severity, typically 30-90 days

Scope

This policy covers:

  • The Cloudflare Worker (src/)
  • The client widget (src/widget/)
  • The hosted instance at bugdrop.neonwatty.workers.dev

Out of Scope

  • Self-hosted instances (contact the instance owner)
  • Third-party dependencies (report to the upstream project)

There aren’t any published security advisories