Security
Reporting a vulnerability
If you find a vulnerability in borehole.dev or in the Borehole collector, write to security@borehole.dev. Write in English or Spanish. The same address is in our security.txt.
What to send
- What is affected: a page or endpoint, or the collector's version
(
borehole --version). - How to reproduce it, and what an attacker could do with it.
- Whether you know of it being used against anyone.
What we ask
- Test only against your own account and your own repositories.
- Do not read, change or delete anyone else's data, and stop as soon as you reach any.
- Give us a reasonable time to fix it before you publish.
We will not pursue anyone who reports a vulnerability in good faith and keeps to these three points.
The EU Cyber Resilience Act
The collector is software we supply in the EU, so the Cyber Resilience Act applies to it. We report an actively exploited vulnerability in it, and a severe incident affecting its security, through ENISA's single reporting platform. You can also report a vulnerability in it to the CSIRT that your member state designated as coordinator, or to ENISA.
See also what happens to your code and the Terms.