Security Policy
Eurosky builds and operates public-interest social web infrastructure on the AT Protocol, including services that hold people's identities and data. We take the security of that infrastructure and of our users seriously, and we are grateful to anyone who helps us find and fix problems responsibly.
This policy applies to every repository in the eurosky-social GitHub organisation, unless a repository has its own SECURITY.md, and to the services Eurosky operates.
Reporting a vulnerability
Please do not report security vulnerabilities in public GitHub issues, pull requests, discussions or social media posts.
Report them privately using either of these routes:
- GitHub private vulnerability reporting (preferred for issues in our code): open the affected repository, go to the Security tab and choose Report a vulnerability.
- Email: security@eurosky.tech.
If you are not sure whether something is a security issue, report it privately anyway. We would rather receive a report that turns out to be harmless than miss one that matters.
What to include
To help us triage quickly, please include as much of the following as you can:
- The affected repository, service or URL, and the version or commit if known.
- A description of the issue and its potential impact.
- Step-by-step instructions to reproduce it, or a proof of concept.
- Whether the issue is already known publicly or being actively exploited.
- How you would like to be credited, if at all.
Please write in English if you can; reports in Dutch, French or German are also welcome.
What to expect
We are a small team, so these are targets rather than guarantees, but we will do our best to meet them:
| Stage | Target |
|---|---|
| Acknowledge your report | Within 3 working days |
| Initial assessment and severity | Within 10 working days |
| Fix for critical or high issues | As fast as possible, normally within 30 days |
| Fix for medium or low issues | In a regular release, normally within 90 days |
| Public disclosure | Coordinated with you once a fix is available, by default within 90 days |
We will keep you informed of progress, may ask you for more information, and will tell you when the issue is fixed. With your permission, we will credit you in the release notes or security advisory.
Where a fix is needed in code we have adopted from upstream (for example the AT Protocol reference implementations, or the Bluesky social app on which mu is based), we will coordinate with the upstream maintainers and may share the details of your report with them for that purpose.
Scope
In scope
- Source code in repositories owned by the eurosky-social organisation.
- Services operated by Eurosky, including:
- the Eurosky PDS and account services at
eurosky.social - the Eurosky Portal at
portal.eurosky.tech - the EU-HAUL migration service at
move.eurosky.tech - the mu social app at
mu.social(andstaging.mu.social), built from eurosky-social-app, including its edge functions and, once released, its mobile apps - other Eurosky-operated infrastructure on
eurosky.social,eurosky.techandeurosky.network
- the Eurosky PDS and account services at
Examples of issues we especially want to hear about: authentication or OAuth flaws, account takeover, access to another person's data, privilege escalation, injection, cross-site scripting, server-side request forgery, leaking of tokens or credentials, flaws in account migration or identity (DID / handle) handling, and, in mu, issues such as session or token leakage in the browser, content injection through posts or embeds, and bypasses of moderation or privacy settings.
Out of scope
- Vulnerabilities in third-party services we do not operate (for example Bluesky's own services); please report those to their operators. Issues in unmodified upstream software (the AT Protocol reference implementations, or Bluesky's social app) are best reported to the upstream project, though we are happy to be copied in.
- Denial-of-service or load testing, spam, and social engineering or phishing of Eurosky staff or users.
- Reports from automated scanners without a demonstrated, realistic impact.
- Missing security headers, best-practice suggestions or version disclosure without a concrete exploit.
- Issues that require a compromised device, a malicious browser extension or physical access.
- Problems with your own account, such as being locked out or a lost password: contact Eurosky support instead.
Testing guidelines and safe harbour
We will not pursue or support legal action against anyone who acts in good faith under this policy. To stay within it, please:
- Only test against accounts and data you own or have explicit permission to use. Create test accounts rather than accessing other people's.
- Do not access, modify, download or keep more data than is strictly needed to demonstrate the issue, and delete anything you obtained once you have reported it.
- Do not degrade or disrupt our services or other people's use of them.
- Give us a reasonable chance to fix the issue before disclosing it publicly.
- Comply with applicable law.
If in doubt about whether something is allowed, ask us first at security@eurosky.tech.
We do not currently run a paid bug bounty programme.
Supported versions
Unless a repository says otherwise, only the latest release and the current default branch receive security fixes. Operators of their own deployments should keep up to date with the latest release.
Security advisories
Fixed vulnerabilities are published as GitHub security advisories on the affected repository and noted in its changelog.
This policy is also published as SECURITY.md on our GitHub organisation, and a machine-readable contact is available at /.well-known/security.txt.
Found a vulnerability?
Report it privately. We will acknowledge your report within 3 working days.