Found a vulnerability in one of our products? We want to hear about it, and we'll act on it.
| Product | Supported |
|---|---|
| Nimbu CLI (Go) | Latest release |
| nimbu-js-sdk | 1.x |
| Nimbu platform (nimbu.io) | Hosted — always current. Report anyway. |
Older CLI releases and SDK versions before 1.x do not receive security fixes. Upgrade to a supported version.
Do not open a public issue for security reports.
Report vulnerabilities by either:
- Emailing security@zenjoy.be
- Using GitHub's private vulnerability reporting on the affected repository ("Report a vulnerability" under the Security tab)
Include enough detail to reproduce the issue: affected product and version, steps, and impact. Proof-of-concept code helps.
- Acknowledgement within 48 hours
- Initial triage and severity assessment within 5 business days
- We'll keep you informed while we work on a fix, and credit you in release notes if you'd like
We do not run a bug bounty program and do not pay for reports.
We will not pursue legal action against researchers who:
- Act in good faith, without fraudulent intent, and within the scope of our coordinated vulnerability disclosure policy
- Go no further than necessary to demonstrate the vulnerability
- Do not access, modify, or delete data belonging to others
- Give us reasonable time to fix the issue before disclosing it publicly
Research conducted under these terms is authorized. In Belgium, reporters are additionally protected by the national CVD framework operated by the Centre for Cybersecurity Belgium (CCB) when its conditions are met.