Skip to content

Security: hetznercloud/cli

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you have found a security vulnerability, please report it privately using one of the following channels:

  • GitHub's private vulnerability reporting: open the Security and quality tab of the affected repository, then click Report a vulnerability.
  • Email: security@hetzner.com

Please do not report security vulnerabilities through public GitHub issues or discussions.

We welcome all reports. If you are unsure whether an issue qualifies as a security vulnerability, please report it anyway. We will review the details and work with you to determine whether action is needed.

When reporting, please include as much of the following as possible:

  • A description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept
  • Affected versions, components, or configurations

Encrypted Communication

We encourage you to encrypt reports that contain sensitive information. You can send OpenPGP-encrypted email to security@hetzner.com using our public key, available at https://hetzner.com/pgp-key.txt.

There aren't any published security advisories