Vulnerability Disclosure Program
Report security bugs responsibly.
Submit reproducible security reports, receive an internal ticket ID, and qualify for CredStore certificate recognition or hall-of-fame placement after validation.
Program Rules
Do not access third-party data, publish active exploit details before remediation, or attack infrastructure outside CredStore-owned surfaces. Good-faith reports are reviewed through the internal ticketing system.
In-scope targets
- CredStore desktop app for Linux, Windows, and macOS.
- CredStore Android APK and iOS app builds.
- CredStore website and static endpoints under
https://locamartin.github.io/credstore/*.
Out-of-scope activity
- Denial-of-service, spam, social engineering, physical attacks, or third-party service abuse.
- Accessing, copying, modifying, or deleting data that does not belong to your own test account/device.
- Public disclosure before CredStore has validated and remediated the issue.
Public recognition is published on the dedicated Hall of Fame and advisory pages after validation.
VDP Ticket Chat
Continue a vulnerability report conversation with your ticket ID. Markdown formatting is supported.
Hall of Fame
Validated good-faith reports are published here after remediation and reporter approval.
Security Advisories
Public advisories include the affected version range, CVSS score, validated impact, reporter recognition, and remediation summary.