Skip to content

Security: REBELinBLUE/deployer

Security

SECURITY.md

Our security policy and Your responsibility

Our security policy is to avoid leaving the ecosystem worse than we found it. Meaning we are not planning to introduce vulnerabilities into the ecosystem.

The "deployer" team and community take all security bugs in "deployer" seriously. Thank you for improving the security of "deployer". We appreciate your efforts and responsible disclosure and will make every effort to acknowledge your contributions.

Report security bugs by emailing the lead maintainer at github@stephen.rebelinblue.com and include the word "SECURITY" in the subject line.

Report security bugs in third-party modules to the person or team maintaining the module.

SECURITY DISCLOSURE:

Your responsibility is to report vulnerabilities to us using the guidelines outlined below.

When disclosing vulnerabilities please include

  1. Your name and affiliation (if any).
  2. scope of vulnerability. Let us know who could use this exploit.
  3. document steps to identify the vulnerability. It is important that we can reproduce your findings.
  4. how to exploit vulnerability, give us an attack scenario.

For critical flaws and sensitive security information you may encrypt your transmission with key below (also available at https://keybase.io/rebelinblue/pgp_keys.asc)

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBF9Iw7oBEADP91myRpT2CyIQEipAQ/umzph/gBl6g878YxgEzaQAWra5528j
GKSAaziwy0UNnIYRVUvTe12O1z9ZEOgZwuRFrJxIyLuDBhh3rlAwDcGiPqKNiz86
n2i05EmpoI59D3PbHaW8xvIb9PuSMvGA05WtVfZW4gLs/eAPXN/6BJkanac8518U
0JXyh5aWDLGruwVbqGgHUjsr71w/5VGJrPqOKyrtngjShxdhuVYQNwz0zCibEGlz
p1nHOVSqArJAxfl2fPY7zHuQtvBa0NyWGUmRyGFTDd6j4x1WqHy63CzAfoa7XzUw
I0bGmpOeFK5VWwEeVDC74IkTqToZn418QyFBByjNFxbYPkttstdRyw+R44XO6bmQ
cymqMkviwk5Gt2wU8zC37pW5D0ApcHyOBTdQhm1j5iJ9o0MOG0yq+0qI++Atlh+X
bcZtAFoY/kemZINwQLRW24y/Hh6WMQKBAGiqdbgwBTXcVtu0m8lMZEZD05QzwmXt
ipklxLUyv3lGrodMMeniHVhY3KmlHeNzUid7mNxaFSs/oPOq0yZQCH6g5JFA/fL5
nsgoXdEYcV7XzRuE2r4s1Dbm26X/wuDBh4ZI9/Kylh9ffEwWGEoztSJz/fQ6+pNY
jppmzgBx3vjAkpDbpuVZqQN/Iz6mnXcvLWI1fXj0DHuWKzqzQ0XHHvQ6nwARAQAB
tCpTdGVwaGVuIEJhbGwgPHN0ZXBoZW4uYmFsbEBsZW5kaW52ZXN0LmNvbT6JAlQE
EwEKAD4WIQTN6/4gmN7jvpcZh0gfcsrkYNn0LAUCX0jEaAIbAwUJEswDAAULCQgH
AwUVCgkICwUWAgMBAAIeAQIXgAAKCRAfcsrkYNn0LG97D/98WIGoIoBs1mu0hVoO
6b60L2Q69sgYipeudnojhK+APfaEZj+S1NyoA18slwz3mA/Pg3E73EeY9Td4Kyq4
uu7FiRJqR3lvTt6X7Q5VIVFHTx7xb5d6OS00Vap9KhAvUTjkCg85YY3s/MN1MQyM
JcKKOh2n9fWwQ2W9qAPHdXxb70UHv3e/Y9J0EtMPVq35/U5RJ/eCWLUHA+rnV8Ur
u7c/cCGIWuifgsx4jZWMbUnYSvXpV2/tntwlztbOXnxFB/u7tSDB98EsA9fUP3Pq
aRkkKVmcCHE93R+l7GeCpZhAkl8nQgGKLx3+j6D4/a+BJ7/7xKvRHTmrH5ELarDp
Mbfe4w1Y40xrf3rwda2n4/diDAx6YpXiNZytCBJL+YaJ+oyHG0dWf2lSZpDmkNL1
2W6M0JDPwgpkmSW/j7jgBbuQE8nWfv1NM2XRZHXCUNzIeaHI+pHPpNVa3ILXNj4O
+t2XMrUrV7FR2CI9WxiBeLi7VEXd26upFKs1WFYA0Pv5QH4EIcjTmD3spI/3QYE0
jD+VI6MB2kFUAgPQRva8fB5dKoutjZohZKw2JBbgD7HTDEDQd0hMRyX7sTNDj/Zn
DFfWj4NtLkeUBErO/UxHtCakjD+s2/nmPHJdCG/aQZg0h2QGxyqCGVscq4R7z/gT
OoCJGREDynZRlUO8tn5OQ0fnXrQmU3RlcGhlbiBCYWxsIDxzdGVwaGVuQHJlYmVs
aW5ibHVlLmNvbT6JAlQEEwEKAD4WIQTN6/4gmN7jvpcZh0gfcsrkYNn0LAUCX0jD
ugIbAwUJEswDAAULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRAfcsrkYNn0LJDA
D/9GmzR2x8ohEn44/CdQdnaA+CI5jIf+0Z1Tx8gZnao/z5CXmZ3DTgLDtDQRw8cK
HgWvrD8i3uRXE0M70EjaHxtA0DifWQtjLUPLORKSR/8z8wRC1zcwOEOqJKw6+pSt
qfpJuuCqhveZkQD/+4tciyOqnMIXWs8jyaq/WVu804MUnDy46ww/iMWl4OYjSwCb
SJeigRuaR4E0HezD0H8b3rQRFfjNN9EXDy+gPJFWChPEcVlvCKqbrUltDQUvScgB
WsKe897xjoo5RQUR9VevGwnwNFmLfVAzdpKabhHyNcE1XOapLriLgNhHym10Zetp
kYmvrqTw1boE5KVX2I66+ODr9XRppItIk98Fkl6DuKKGQS9Ei0nQegqqXspzN83O
Up79B1DkM6G8di4wbAq4YQS46VZkbW8q/gos6CtEXorXb+o5IjdXW1GBYeEIe7YY
EO1/o08MMfj6Wm4P2eFJohLUZRuwFxBpmWPQE2q7VOLRMb6ZJIT6LhwJKkFW4RiA
Ex190AN9PPZYP2DqCuIbL1SXi2zpXYV7Q9j2dkssM9tXrg1vOG/OcfC3D22Y1zGA
xNFMx6lHvRP3R9aQM0VMe03JZjNu4I5Z+aVWMz6uDMvbBNJHIkzCewCZu4UJIYwI
weVetCVLxGKfgB6Ch8qcLrZ6P9FehRp7uDURnqjeZIrI7LkCDQRfSMWAARAAp8Lz
rajpCf32S4G82XI3JqkQ9KxSXK7/m5y1kgtxhTB/rrhCctzNocBUlHyIjMRkjBHQ
+t2w/N08SPO4J2kEXzmlhTDaXDzEUeWW/Kgulzj60TY3ULKPzf76kIqxfH3pEN09
HU0wr5TxqTQq7JddMCJ70FjBu5Z7eGa52TIAerEp1Jz7YJfJvzheDifjQ9dg82OK
bvmKocEohfVQV0Kwde4xypUo42SoUeAKBTydrX+o0eITa2x3gzxNbE4aC3JzYesa
sVp6o1dYfPbhx+uQBe3GoOR3j6EB5ChEnFslrafOz+4DK8Abhgnfxrhl559lxTIX
jLveSB1k55bSHI6as1uUxdjqPqW4sxO0sDAzDZzs2JraZS72bHnY9dHXZNmdxwG2
DnZS64nQVdBtnbVJRaHkezDg+Sr1B+6Z2OCSvWx8nSivcR9rWAdyryjSWjUYnFEM
2MaYsBA3SVKr2dLV+in/CWYg5yvtbyxSeR4dDpg8ac4UIje0PgCYNA8o6f6i3irp
Q8pUYbd825qmDwtP7l/tZnlYmIQ4GuriJhpa05PeWEgKZ2Jug0T77U8sGd3rFrD1
gwheNcKL3eo3cPJ/aCos6qGUYM5QEg69Xe45o3w7A5EJywiXsTd1+pdZ/QCEAsfI
eZfzAHHSB48rkWSbwRHKUWKJ18UUHwO8k1FavisAEQEAAYkEcgQYAQoAJhYhBM3r
/iCY3uO+lxmHSB9yyuRg2fQsBQJfSMWAAhsCBQkSzAMAAkAJEB9yyuRg2fQswXQg
BBkBCgAdFiEE4izi17PLfQMQbbBsoLuXGFOstCkFAl9IxYAACgkQoLuXGFOstCkL
bQ//WDXR/xqscicSSu6wk2rqgps0PTyZQrRjoS0LAEHTYEgR5jcWDPnQV0+5WKy9
ot21HNjolPh8kVW+EgaThSVQqfwmaM7Ha5fHdB49qvk01KM76TiCPHWvmLaujGO9
exolTkuWnXNZRnd30I+AaVYJe3osA0nkkrL/lV3BhKgzqorDYxHmUEFgPqpe0lKQ
vcnyvFe7qu67rtYgXZ25ugcIZeZOrgrBdP4ZWWyaStZIBDfd8RnzYBlChxYtJ4My
YWyVmuLblzONooE4xI6FsDoDA3EDB0xIh/1qLy7FzHoyFZE25kq8qBGFCJuj48B8
jZ3wRT8tMJXKfbnuABx34DycXILrFe98YD25Kw8TPfyDOZX6pzvbYE7EeYOB0tU+
sxu3y5ukzkS+vH4lM/SVYe/a+A2o6EFhh04xh4hleg/mBCT8s/UPXnGMwiMMOQtL
ghciw6mKiFUvYKYyX4tSkPpdktceexrlzKb3ARdxGUyn53Fg78po2eXlnyVOn7HZ
IFhrunNWcRO0E8i0HpPtAOSPajvGNJ98RsKRWGbWSElkzdobe8JGA6rfJFfbo+hF
GZmzoSCV6fYPHp4Ii1ywd1f4qiHQVr+kLy3IjnZK+oBRC1VydOJ3q9jp+NFJ0eiY
A3t2ujP/8wbVApO/QzEQkrVX6RjlUQU6YLZPG4ruVLlnzn1wZhAAlVLqdJi2s6wt
6UzK2ks935ctdrTdhUwZVz4Yi0w04Z7mD713raPDV6+cn16rgXm9OwtTmEzTcTjy
HFDfQq4W2lmNDTiNNR+yRcqF8wZbLH73U9rnBsEhKe9HXHEbRyVNSw+t+xddAF4i
7rMqfDNejovI6j2p3IsKHRcq5JDtSrl0Wx5t7MefmkOCk6qszBR9adDOV/oShkOa
vWxuQth1I3+Jg0cnSWAM8yvpvoXlQGdtHDdQ6HjG+dXwOJmrfJrNf3vy/ODlvnjR
rr7hqbDII4dWMU7BsiY2Wq9vd70EmAJeKlGGtGKJSO5xM7P3geT0I5r2MQsowPZ8
4RPHmy+SbbHDDn3bk5WanqmvcXuKZbG/AIbG738rMos9vv/7GfBJgmfZ13ybk0wI
SgtCt1LiMFB6ni/Hy/2HA5b0RGKgrdZVzDB9fy7dGHTMI6fEltEQDJaP/UAbHTI6
sqygx6G9UcQIenIwHw6IFeAaRJ0A5Bc1+hERoKrKcLH/uprs08QDwXdfOuIHcGEc
Oj03ozfzEyuThLlP8m1eCGg0bkusGj5XsuVH+AcNF3gV7qgQTGbVePtjO94eb/Ss
kXNjZ2zVfFpus36MOaDslagtFoZxvMiPP78b/+UZeMZfk5NaeL0Y6TLottEDIzzR
+FKdXSV+bu0MpeKJFh9qedkzp4uueBW5Ag0EX0jFugEQALe9bqRPP/nObwTJQZkA
zqM0Q2vzDqyXV8gwN4ySa9izpvpapHpMfh9J534M8B24Ruq9Y7t8TSIGj78uCeZR
hc9ICmORyziEW2qq0YYqgYsYRjNvxcFaAlI58xmRDPxISAeCtRmgSpZmOExXPru9
5eqdNK9gkYdt8xAvErrXgMl/rRY8kSbweWEtI7Yju0nLRc5aQmmr0TpNJ5AVmYri
5Hdze0neaF1WqXA73Ou2cyigdWtqjEkZQkoyu+YTsfcu5oJgCYOnNclRywhkAMtb
rXZwWZYAoIh3pxepCjXzcl7LXD69EunWpLRsdRZKRhKB9R5ENyoLMKoU8FgQNiHn
4eOG+8Xi69EZjBRAWqdUk1vZ81Jzz/7MLck/GpuLcd3bt2pON1tVDVmv3X8xXaEz
rY6UaFq73bjT3yec9TpzS93F3NB6e7+zGRJMW7M8L8lawnkeVNO505Gig+eevLFb
Z/ucHvlhi5FlvjN7m8KKNuujWOVZogEN9vT2sdoAKSxrZj4y+mNiCQJ5wBqjtGdF
wEJtXO42Bxj1nx9Av3VZVVyeDYx3202wX+y11ERqFUGYTDron4DOgXcNzVKhmHNm
6fYok7Wi9qMkX6QbHADvBsRKzjnDJAjuRgoAWORLWveheg/7ntFLNciuyNKCREt2
OkW36RXnal+dLGDtfkDMyQrhABEBAAGJAjwEGAEKACYWIQTN6/4gmN7jvpcZh0gf
csrkYNn0LAUCX0jFugIbDAUJEswDAAAKCRAfcsrkYNn0LDbmD/40geIPlnc5/Oxn
cTzxY0Hz0sRyKOBVTa6w244pywoM7lFM2K/Ne5xCcaF8NNugRWAYNYPxe3M0B82t
xEQwoQiSxbjC05EceuRrnpV+0VKpOwskTJi4aw3AfM4OBvPYC7IWLBZq6OIgyBzY
j7UqdI4pnfcbxxcEdW+AMmX/nQ1WwllMWUzw5EYu4M0rLhqKgO8awCQwmo01yC/z
c9UmKJsOQOLdkearoVhFvOu9FtGdk2kuUTHvfl0PaYRdumCtH0u/QP7ywxOehHui
+H69hYIRvA+wOz/mgQKgMc05Tk8dZkfo5zZdpXgqSZ35lglZBNxENGlysAe/h2bt
Fr1Ifk0C/surgkrzfbZjCrDaB3SmWai9kniz1t2e1ILg5cjL2adR9Mkpxc5m6BQC
tEBJ1Y0rWmj5w8pj53dQAS7Dtrv+asgDxp48xwu1rVXwhCFmy5TRvU3GOvK1tVIi
tnEfezvoph54+GSbwWnr1eoCpnrE4bX0/AGArUfdNhsLXrKQc1/YXXTxc2ScxZkv
exrsq2gz8HaZu1CCNtA9m/Nv0pyorUOidw/MlCmi3z5o6Wi/PHp0Sp7SktvUmOL7
5R7OQ3xr3nHO9k5pCu/HTS9y67MoslQY4WhRVcDnETxqbXpGC8WRgdcmVdyjJ4/l
DROg3Mwz5cxBR+i/YuuOP+3WRG/ChrkCDQRfSMYHARAAuUO0yliPkvp4vdrKEvUh
cPdNq1HH5V5Ltl4NQE5zI8aC9w0qVdBYGbIpTD9PHl8tI5vTtQcBcJBi41+vWLFb
wIjoReRi41B14fxtFWQ/LtOY9C5GIephzkBKfaxYoUZK4UAUVxnzSYjWPDTVL08K
7e5J5x/1FGGKwu3knOlNpzQLr2YrcKNlzJrngJOwGsh9myNS8iPg7YDHqq9R/ppD
v03/rj7/+JfLp4aStBuDuLiVrYRt/vCe8Xa6N8lRnsBGqLPacw0yvbE+C1Qki/Wm
cFuQdexDfnNeILdXu7jJcmT5HABhRAlu+ki10MMsBg+uUsu3HnrvX97hLYixAXOZ
tf2lW79pCAynaJBuwget5Ojha3oJNeqlRPvwqJnCx6BPxAFc3nvvC52o8UnLuO3G
NJhya60vwyz8LjAoWQ+TW9Dsz1Cf2esR5WyewQIj5OiOuF9vZVmcWeSVoreuDq4Z
F30Yg9AIJi6F0GToDQJ6t+fAGn4xZPb4laDLhIULngTQfUHJwN9NvsmmErWLKaHu
kJ05nd6GQercnDrWqxgep4v4XFVFKo4qsWPFnvHZ5PoXNMOLk54E6pTOzyIMIP1l
zAvIXRQIKyURXDyFdBK+hFfb2CBteGEtZPX4kYDzK1gb0Oq0QsaUHgRlqCzmhBdt
Cr/u7gaXVqx733O6bmsCuMMAEQEAAYkCPAQYAQoAJhYhBM3r/iCY3uO+lxmHSB9y
yuRg2fQsBQJfSMYHAhsgBQkSzAMAAAoJEB9yyuRg2fQs1WcP/03THlKK4rBH3zK7
/1RwHhTMc2tGIYvYz3hHFmVdrCazz6OOSjJal5Dku3uKi/8qBRpV3vLVmH5XxR0/
xwwzPaE8EWw7YJ+7tMi2AGjRgbukEBHn9wLOMJ4QhHxRacaQJZ2jBMIgKePyuX0+
BDkEYQ1lA9UxDqp7jI0H4J/odNYdN9exNcvD1BfNpphNL6L9azgXhHwJoXzh0pHe
ZbGIAK/NjrQiSTs3XXbubQHGVvh28wDmPiB/b7d/HsKcO2SNm66TeJqdVDQ+U/V4
aST2GA+Th7oOPxX7elXG8Xr8WDtxLAUKoT64zIpcDy+c0GDkq6d0VfwPaHwIttiq
tjgcqDPV8U3AyhbbMiabodBSvTRk3TSZ6WWdnul/kBBYs47CL3Vq2hvPTOsEPBvS
3i1mu4Gk8rufISu5G1glOnMuWv0oKBbjs8srsPt3jFvB6UMPVA4MIdEflmvRGp6p
0+18Kf4ZSn7hoatLF2wEnP7qNqpBebv2f3Hh9qzRCrqyTOpYmrLISlRLuJYCpNr5
F2xSymLiJGuMEZmdZwviAgs7kiExN0K11NFiz+HQkFJpyrRj/r03cUVQgorbTPYF
x4guFjE+a9lnUFesd005c77166WFH9CQWvh0Z+d3+d37Pda3eBn2vdl8uMyWjc/h
mPGnf3IkVWvUzlhzrIa+zHsDm8ae
=UdoP
-----END PGP PUBLIC KEY BLOCK-----

There aren’t any published security advisories