Backstage · Vulnerability Disclosure

Backstage Vulnerability Disclosure

Vulnerability disclosure

Backstage runs a coordinated vulnerability disclosure program on Hackerone.

Developer PortalInternal Developer PlatformSoftware CatalogOpen-SourcePlatform EngineeringSoftware TemplatesCNCF
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
source: https://github.com/backstage/backstage/blob/master/SECURITY.md
provider: Backstage
providerId: backstage
has_program: true
policy_url: https://github.com/backstage/backstage/security/policy
policy_file: SECURITY.md (backstage/backstage)
bug_bounty:
  platform: HackerOne
  url: https://hackerone.com/spotify
  note: >-
    Backstage directs sensitive security reports to Spotify's HackerOne bug-bounty program rather
    than to GitHub issues. Backstage was created by Spotify and donated to the CNCF; the bounty
    program remains Spotify's.
reporting_channels:
  - channel: bug-bounty
    target: https://hackerone.com/spotify
    preferred: true
  - channel: discord
    target: https://discord.gg/backstage-687207715902193673
    detail: "#security channel, or DM a maintainer, for questions about a potential vulnerability."
advisories:
  mechanism: GitHub Security Advisories
  url: https://github.com/backstage/backstage/security/advisories
  cve_requested: true
  detail: >-
    The published runbook requests a CVE early, develops the fix in a private fork, and publishes
    the advisory alongside the release.
supported_versions:
  policy_url: https://backstage.io/docs/overview/versioning-policy#release-versioning-policy
dependency_scanning:
  tool: Snyk
  detail: >-
    Ignore rules are stored in in-repo .snyk policy files so adopters can inherit the project's
    vetted exceptions.
security_txt: false
security_txt_note: No /.well-known/security.txt is served on backstage.io (404 probed 2026-09-04).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/backstage-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.