Skip to content

Security: aimlesx/cookidoo-openapi

SECURITY.md

Security policy

Repository vulnerabilities

Use GitHub private vulnerability reporting when it is available for this repository. If it is not available, ask the maintainer for a private contact channel without disclosing sensitive details publicly.

This policy covers vulnerabilities in this repository, its tests, and its build tooling, including accidental publication of secrets or personal data. The project offers no bug bounty.

If a credential was exposed, revoke it immediately. Do not wait for a repository response before protecting the affected account.

Cookidoo or Vorwerk vulnerabilities

This repository cannot authorize testing of Cookidoo or any Vorwerk system. Do not open a public issue or pull request containing a suspected service vulnerability, bypass technique, credential, account identifier, or private response. Vorwerk publishes a security reporting procedure and the address security@vorwerk.com on its security and privacy page.

The existence of that reporting channel is not permission to test. Follow the service owner's instructions and applicable law.

Never attach

  • passwords, authorization values, cookies, CSRF values, or client secrets;
  • HAR/PCAP files, browser profiles, cookie jars, or authenticated dumps;
  • account, customer, device, serial, Cook-Key, IP, or correlation identifiers;
  • recipes, notes, images, videos, or other Cookidoo/user content.

There aren't any published security advisories