This document outlines security procedures and general policies for the Hoppscotch project.
We use Github Security Advisories to manage vulnerability reports and collaboration. Someone from the Hoppscotch team shall report to you within 48 hours of the disclosure of the vulnerability in GHSA. If no response was received, please reach out to Hoppscotch Support at support@hoppscotch.io along with the GHSA advisory link.
NOTE: Since we have multiple open source components, Advisories may move into the relevant repo (for example, an XSS in a UI component might be part of
@hoppscotch/ui
). If in doubt, open your report inhoppscotch/hoppscotch
GHSA.
Do not create a GitHub issue ticket to report a security vulnerability!
The Hoppscotch team takes all security vulnerability reports in Hoppscotch seriously. We appreciate your efforts and responsible disclosure and will make every effort to acknowledge your contributions.
We receive many reports about different sections of the Hoppscotch platform. Hence, we have a fine line we have drawn defining what is considered valid vulnerability. Please refrain from opening an advisory if it describes the following:
Hoppscotch Team ensures security support for:
In case an incident is discovered or reported, we will follow the following process to contain, respond, and remediate: