Use GitHub private vulnerability reporting when it is available for this repository. If it is not available, ask the maintainer for a private contact channel without disclosing sensitive details publicly.
This policy covers vulnerabilities in this repository, its tests, and its build tooling, including accidental publication of secrets or personal data. The project offers no bug bounty.
If a credential was exposed, revoke it immediately. Do not wait for a repository response before protecting the affected account.
This repository cannot authorize testing of Cookidoo or any Vorwerk system.
Do not open a public issue or pull request containing a suspected service
vulnerability, bypass technique, credential, account identifier, or private
response. Vorwerk publishes a security reporting procedure and the address
security@vorwerk.com on its security and privacy page.
The existence of that reporting channel is not permission to test. Follow the service owner's instructions and applicable law.
- passwords, authorization values, cookies, CSRF values, or client secrets;
- HAR/PCAP files, browser profiles, cookie jars, or authenticated dumps;
- account, customer, device, serial, Cook-Key, IP, or correlation identifiers;
- recipes, notes, images, videos, or other Cookidoo/user content.