Skip to content
Pug Network Docs Open the app

Security

Report a vulnerability

Pug Network is a security-focused product. We take vulnerability reports seriously and want to make it easy for you to send one in. This page explains scope, what to include, what to expect back, and how we disclose fixes.

How to reach us

Send vulnerability reports privately. Do not file a public GitHub issue — that broadcasts the bug before we can ship a fix.

If you require encryption, ask in plaintext for our PGP key and we will send it back. The key fingerprint is also published in the repository root SECURITY.md.

What is in scope

What is out of scope

What to include

A good report includes:

What to expect back

StageTarget
Acknowledgement of receiptWithin 72 hours.
Triage and severity assessmentWithin 7 days.
Fix or mitigation in mainCritical: 14 days. High: 30 days. Lower: best effort.
Coordinated public disclosureAfter fix ships, by mutual agreement.

Targets are aspirational, not contractual — Pug Network is currently maintained by a small team. We will keep you updated honestly if a timeline slips.

Disclosure policy

Safe harbor

We will not pursue legal action against good-faith security researchers who:

If you are unsure whether your planned testing is in good faith, ask first — we would rather have the conversation than miss the report.