Skip to content

Security

Report suspected Cadevil vulnerabilities privately to the security contact. Deployment-specific contact details are available in security.txt.

What to include

Provide the affected version, impact, component and a minimal reproduction with synthetic data. Include the response’s X-Request-ID when available. Keep passwords, tokens, private signing keys and customer models out of the report; agree a secure transfer channel before sharing sensitive attachments.

Coordinated disclosure

Allow time to investigate and coordinate a fix before publishing exploit details. Response and fix dates are agreed during triage. There is no promised response deadline or paid bounty. Assess only instances and accounts you are authorized to test.

Supported versions and release evidence

Security fixes target the current 0.15.x release and development branch. Older versions need an upgrade unless a backport is agreed. Third-party plugins and deployment-specific drivers need separate maintenance.

Download the release SBOM (CycloneDX JSON). Dependency inventories and the code audit describe their scope and limitations; a clean scan does not guarantee security.