Skip to content
Updawg

Security and Vulnerability Disclosure

Last updated 6 October 2026

Updawg decides what gets installed on other people's servers, so we take reports about its security seriously and would much rather hear about a problem from you than from an attacker. This page says how to report one, what we commit to in return, and the rules that keep your research on the right side of our terms.

How Updawg is built to make attacks hard in the first place, from signed jobs to the isolated signer, is in our security whitepaper.

How to report

Email security@updawg.net. Please include:

The same address is listed in our security.txt. Please don't report vulnerabilities through public GitHub issues.

What we commit to

We do not run a paid bug bounty. If that changes, it will be announced here.

Coordinated disclosure

Please give us the chance to fix a problem before you publish it. We ask for 90 days from your report, or until a fix has shipped, whichever comes first. If a problem is being actively exploited, we may publish sooner, and we will agree the timing with you where we can.

Safe harbour

If you act in good faith and follow the rules on this page, we consider your research authorised, we will not take legal action against you or ask anyone else to, and we will treat it as permitted under our terms. If somebody else brings a claim over research that followed this policy, we will make it known that it was authorised.

Good faith means that you:

In scope

We most want to hear about anything that could let someone reach another organization's data, run a job or install a package on a host that nobody approved, or get the agent to accept something we didn't sign.

Out of scope

Not sure whether something counts? Report it anyway. We would rather read one report too many.