Scope
In scope:
- The website and account API at
privatecrates.dev, and registries at*.privatecrates.dev. - The registry protocol as we implement it: sign-in, token exchange, permissions, publishing, yanking, search and downloads.
- How our GitHub Apps use their permissions, including anything that lets us, or anyone else, write to a storage repository in a way the verifier does not report.
- The open-source tools: the credential provider,
cargo privatecratesand the verifier.
Out of scope:
- GitHub, Stripe, Railway and Cloudflare themselves. Report those to them; tell us too if it affects PrivateCrates.
- Denial of service, load testing, spam and social engineering of our staff or customers.
- Reports from automated scanners without a demonstrated impact, such as a missing header that enables no attack.
How to test
- Test against a GitHub organisation and registry you own. Organisations with up to 5 members are free.
- Do not access, change or delete other people’s data. If you reach any by accident, stop, and tell us what you saw.
- Do not degrade the service for others.
- Give us 90 days to fix a problem before you publish it, or less once a fix has shipped. For a complex problem we may ask for longer, and agree it with you.
Safe harbour
If you follow this policy in good faith, we will consider your research authorised, will not pursue legal action against you over it, and will not ask anyone else to. If a third party takes action against you for research that followed this policy, we will make it known that your work was authorised.
During the private preview this commitment is given by the operator named in the private preview terms. It will be reviewed by a lawyer, and given by the company that runs PrivateCrates, before general availability.
What to include
- What the problem is, and what an attacker could do with it.
- Steps to reproduce: the requests, commands or code, and the registry, organisation or crate you used.
- Whether any data other than your own was involved. Please do not include tokens that still work; revoke them first.
- How you would like to be credited, if at all.
Encrypted email is not offered yet; it is on the roadmap for general availability.
What happens next
- Acknowledgement: within 3 business days.
- Triage and first assessment: within 5 business days, on a best-effort basis during the preview.
- Fix: critical problems (tokens, crates or another organisation’s data exposed, or publishing without permission) within 7 days; others as soon as practical, on a best-effort basis during the private preview. We tell you when the fix is deployed, and post on the status page if customers need to act.
- Credit: with your permission, we thank you by name in the release notes of the fix. We do not run a paid bug bounty.
The same contact is published in /.well-known/security.txt. For how the service is secured, see the trust centre and the security model.