Skip to content

Security: kosli-dev/cli

SECURITY.md

Security Policy

Supported Versions

Only v2 of the Kosli CLI is currently supported! Please try and use the latest release before reporting an issue.

Reporting a Vulnerability

Please send all reports to security@kosli.com and include:

  • Clear description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any supporting evidence (screenshots, logs, PoC)

Please report privately by email rather than opening a public issue or pull request, and give us reasonable time to ship a fix before disclosing publicly. This repository is public, so anything raised here is disclosed to everyone at the same moment it reaches us.

Bug Bounty

There is no bug bounty for the Kosli CLI, and reports against it do not qualify for a payment.

We do run a paid bug bounty for our production platform, app.kosli.com and its supporting APIs, and for www.kosli.com. The scope, testing guidelines, eligibility criteria and bounty rates are published here:

https://www.kosli.com/vulnerability-disclosure

CLI reports are still genuinely welcome, and we would rather hear about a problem than not. We will acknowledge your report, assess it, tell you our determination and reasoning, fix what needs fixing, and credit you in the release notes if you would like us to.

Our Commitment

Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we're committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we'll explain our reasoning.

There aren't any published security advisories