Skip to content

Security: BlueprintFramework/hydrodactyl

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Hydrodactyl, please report it privately by emailing naterfute@blueprint.zip.

Warning

Please do not report security vulnerabilities through public channels or GitHub Issues. Public disclosure before a fix is available may put users and deployments at risk.

We will make every effort to acknowledge and respond to reports as soon as possible. In some cases, it may take a day or two for us to coordinate internally, investigate the report, determine its severity, and assess its potential impact.

When reporting a vulnerability, please include as much relevant information as possible, such as:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce the issue.
  • The affected Hydrodactyl version(s).
  • Any relevant logs, screenshots, or proof-of-concept information.

Disclosure Process

Once a vulnerability has been confirmed, we will work to develop and release an appropriate fix.

For affected versions, we will create a GitHub Security Advisory and coordinate public disclosure. We generally aim to disclose the vulnerability two to four weeks after a release containing the fix, giving users reasonable time to update their installations.

We appreciate responsible disclosure and the time taken by security researchers and community members to help keep Hydrodactyl secure.

There aren't any published security advisories