Please do not report security problems through public issues, discussions or pull requests.
Email security@scadable.com with:
- what you found, and where: the URL, endpoint or repository;
- the steps to reproduce it;
- the impact you think it has;
- how we can reach you.
We reply within five business days. When we confirm a problem, we rate its severity and fix it on the timeline that severity sets.
SCADABLE does not run a bug bounty program.
Only the default branch is supported. A fix is made there and reaches users in the next release or deploy.