autter.dev is a security product. We take vulnerabilities in our own infrastructure seriously and try to handle reports quickly and without friction.
Email security@autter.dev with the details.
Include as much as you can: what you found, how you found it, and whether you have a proof of concept. You do not need a polished writeup. A clear description of the issue is enough to get started.
We will acknowledge your report within 48 hours and follow up with a timeline once we have assessed the severity.
- Give us a reasonable amount of time to fix the issue before disclosing it publicly. For most things, 90 days is reasonable. If you think a shorter window is warranted, say so in your report and we will talk.
- Do not access, modify, or delete data that does not belong to you while investigating.
- Do not run automated scanners against production infrastructure without coordinating with us first.
- We will not pursue legal action against researchers who act in good faith.
- We will keep you updated as we work through the fix.
- We will credit you in the changelog entry when we ship the fix, unless you prefer to stay anonymous.
In scope: anything running at autter.dev, the GitHub App, the analysis pipeline, the API.
Out of scope: social engineering, physical attacks, denial of service, issues in dependencies that are already publicly disclosed.
We do not have a bug bounty program yet. If that changes, this file will say so.