#Critical Vulnerability Led to Account Takeover
1 messages · Page 1 of 1 (latest)
Hi @vernal mantle. I'm kapa.ai, your friendly support bot. I will try to answer your question by searching through the knowledge base. :wave:
Thank you for reaching out about this important security concern.
The knowledge sources I have access to do not contain any information about a bug bounty program or a formal responsible disclosure policy for Trigger.dev. I cannot confirm or deny whether such a program exists based on the available documentation.
For reporting a critical security vulnerability, I'd recommend reaching out through the following official channels mentioned in the docs:
- GitHub: Open an issue (or, for sensitive matters, consider a private security advisory) at the Trigger.dev GitHub repository. [Contributing]
- Contact form: Reach out directly via trigger.dev/contact. [Alerts limits]
- Discord: Join the community Discord at trigger.dev/discord and contact the team directly. [Getting help]
⚠️ For a critical vulnerability, I would strongly advise not posting details publicly (e.g., in a public GitHub issue or Discord channel) until the team has had a chance to review and address it. Use a private channel or GitHub's private security advisory feature instead.
The Trigger.dev team will be best placed to direct you to the appropriate disclosure process.
Note: you can ask me a follow up question by @ mentioning me again :speech_balloon:
@vernal mantle Kapa.ai is still learning and improving, please let me know how I did by reacting below.
@scarlet belfry