Skip to content

Security: Spandan2022/VertxAI

Security

SECURITY.md

VertxAI Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Vertex AI, please report it responsibly via GitHub’s security advisory system:

Submit your report here:

Required Information for Reports

To help us assess and address the issue quickly, please include:

  • A clear summary of the suspected vulnerability
  • Detailed explanation of the vulnerability’s impact and scope
  • Proof of Concept (PoC) demonstrating the vulnerability (code samples are required; videos optional)
    • PoC must show how sensitive data or functionality can be compromised; trivial UI alerts are not considered vulnerabilities
  • Impact assessment (who and what is affected)

You may optionally include an estimated CVSS 3.1 score; we will review and adjust as needed. We will handle CVE requests internally.

Response and Disclosure

  • We commit to responding within 72 hours of your report.
  • Verified vulnerabilities will be patched promptly, typically within a few days depending on complexity.
  • We follow a coordinated disclosure process: patches are released first, followed by a public advisory after a waiting period (2 to 8 weeks based on severity).
  • Please coordinate with us before any public disclosure to avoid premature information release.

Security Process Overview

  1. Vulnerability submission via GitHub Advisory
  2. Internal tracking and communication with reporter
  3. Validation and impact assessment
  4. Patch development and testing (with reporter collaboration if applicable)
  5. CVE request and advisory preparation
  6. Patch release with initial notification
  7. Coordinated public disclosure after mandatory waiting period

Reporting Channels and Bug Bounties

  • We only accept security reports through GitHub’s security advisory system.
  • If you cannot use GitHub, email us at info@refine.dev to open a security ticket; note that private collaboration may be limited without a GitHub account.
  • We do not accept vulnerability reports via:
    • huntr.dev or other third-party platforms
    • Direct messages to team members (Discord, Slack, email)
    • Public forums such as Stack Overflow

Currently, Vertex AI does not offer bug bounties, swag, or monetary rewards for vulnerability reports.

There aren’t any published security advisories