generated: '2026-08-27' method: searched source: https://github.com/woodpecker-ci/.github/blob/main/SECURITY.md published: true policy_url: https://github.com/woodpecker-ci/.github/blob/main/SECURITY.md raw_source: https://raw.githubusercontent.com/woodpecker-ci/.github/main/SECURITY.md http_status: 200 probed: '2026-08-27' contact: email: security@woodpecker-ci.org method: private email public_issues_permitted: false policy_text_summary: >- "We take security seriously. If you discover a security issue, please bring it to our attention right away. Please DO NOT file a public issue, instead send your report privately to security@woodpecker-ci.org. Security reports are greatly appreciated, and we will publicly thank you for it. If you choose to remain anonymous, we will respect your request and keep your name confidential." recognition: offered: true form: public thanks, with the option to remain anonymous bug_bounty: program: none platforms_checked: - hackerone - bugcrowd - intigriti note: No bug bounty program was found on any platform. security_txt: served: false probed: - url: https://woodpecker-ci.org/.well-known/security.txt status: 404 - url: https://ci.woodpecker-ci.org/.well-known/security.txt status: 200 result: miss note: SPA catch-all returned HTML, not an RFC 9116 document. checked: '2026-08-27' gap: >- The disclosure policy exists and names a dedicated security@ address, but it is only discoverable on GitHub. Publishing the same two facts as https://woodpecker-ci.org/.well-known/security.txt would make it machine-discoverable at no cost. advisories: channel: GitHub Security Advisories on woodpecker-ci/woodpecker changelog_section: >- Each release changelog carries a dedicated "🔒 Security" section — 3.18.0 (2026-08-24) lists five security-relevant changes. url: https://github.com/woodpecker-ci/woodpecker/security/advisories