Security
Report a suspected vulnerability through GitHub private vulnerability reporting. Never put exploit details in a public support or bug issue.
On this page
Report privately
Report a vulnerability privately
Include:
- the affected component
- the impact
- reproduction steps or a proof of concept
- a suggested mitigation, if you have one
Remove credentials, personal data, and third-party secrets.
Response and disclosure
- Acknowledgement
- Within one weekday
- Initial triage update
- Within three weekdays
Public-beta targets, not guarantees or contractual service levels. Channels are not monitored continuously, and CloudChef does not provide 24/7 or real-time emergency response. No fix date is promised. Coordinate public disclosure after affected users can be protected and a fix is available.
Scope
- Covered
- CloudChef’s code repository and the service at cloudchef.build.
- Not covered
- Testing Cloudflare, GitHub, customer-controlled deployments, or other third-party systems is not authorized. CloudChef cannot bind third parties or law enforcement.
Test only accounts and resources you control. Do not:
- access, retain, or alter another person’s data
- disrupt service
- use social engineering
- create avoidable privacy, safety, or financial harm
Stop and report if you encounter sensitive data.
Not an incident channel
Contain the incident first: revoke exposed credentials and CloudChef’s Cloudflare authorization.
- Compromised Cloudflare account
- Cloudflare support
- Immediate danger
- Local emergency services
- Everything else about CloudChef
- Support