Skip to content

Security: gfargo/subpath

Security

SECURITY.md

Security policy

Reporting a vulnerability

Email support@subpath.dev. Do not open a public issue, and do not post details in Discussions.

Include what you found, how to reproduce it, and what an attacker could do with it. If you have a proof of concept, attach it to the email rather than hosting it somewhere public.

I am one person, so response time depends on the day. Expect an acknowledgement within a week. If you get nothing after that, send a follow-up, because the first message may have been filtered.

Scope

In scope:

  • subpath.dev and its subdomains
  • The Subpath desktop app
  • The hosted API that backs cloud documents, accounts, and billing

Out of scope:

  • Reports generated by an automated scanner with no demonstrated impact
  • Missing hardening headers or TLS configuration preferences with no working attack
  • Denial of service through traffic volume
  • Social engineering, physical attacks, and anything targeting a person rather than the software

Testing rules

Test against your own account and your own documents. Do not access, modify, or delete anyone else's data. If you stumble into someone else's data, stop, and say so in the report.

Do not run load tests or automated scans against production.

What you get

Subpath is a small independent product with no bug bounty budget, so I cannot offer payment. I will credit you in the release notes for the fix if you want the credit, and I am glad to confirm the timeline in writing if you are disclosing publicly later.

There aren't any published security advisories