Security

Security and responsible disclosure

How to report a vulnerability in Talarurus software or on this website.

Reporting a vulnerability

If you believe you have found a security vulnerability in Hammerhead, another Talarurus project, or talarurus.com, please report it privately by email to ammaar@talarurus.com.

Good-faith reports are welcome. Please do not disclose a suspected vulnerability publicly, including in a public GitHub issue, until it has been addressed.

Scope

  • Hammerhead and other software published by Talarurus.
  • The talarurus.com website.

Issues in third-party services, such as GitHub or Cloudflare, should be reported to those providers directly.

What to include

A useful report usually contains:

  • The affected project and version (for example, Hammerhead v0.1.0) or the affected URL.
  • A description of the issue and its potential impact.
  • Steps to reproduce it, and a minimal proof of concept where possible.
  • Relevant details of your environment, such as operating system and how the software was run.
  • Whether the issue is already publicly known.
  • Whether, and how, you would like to be credited.

Testing guidelines

When researching a potential issue, please:

  • Do not perform destructive testing, or anything that could degrade or disrupt the website or other services.
  • Do not run denial-of-service tests or high-volume automated scans against talarurus.com.
  • Do not access, modify, or delete data that does not belong to you.
  • Do not violate the privacy of others. If you encounter someone else's data, stop and include that in your report.
  • Do not use social engineering, phishing, or physical attacks.
  • Test Talarurus software in an environment you own and control.

What to expect

Talarurus reviews good-faith security reports and aims to acknowledge them. We may ask follow-up questions while an issue is investigated. Please allow reasonable time for a fix before any public disclosure; we are open to coordinating disclosure timing with you.

Other notes

  • Talarurus does not currently run a paid bug bounty program.
  • No PGP key is published at this time. If your report includes sensitive details, send a short initial email without them so a suitable way to share them can be discussed.
  • This page is guidance for reporting security issues. It is not a contract and does not grant authorization beyond what is described here.