Ballerina · Vulnerability Disclosure

Ballerina Vulnerability Disclosure

Vulnerability disclosure

Ballerina publishes a full vulnerability disclosure policy on its own site, with a dedicated reporting address, a PGP key for encrypted reports, a stated acknowledgement window and a reward/acknowledgement program run by WSO2. It is not mirrored to /.well-known/security.txt (probed 404 on ballerina.io, 2026-09-04), so the policy is discoverable by humans and not by machines.

Ballerina runs a coordinated vulnerability disclosure program on Hackerone.

IntegrationOrchestrationsOpen-SourceProgramming LanguagePackage RegistryDeveloper ToolsCode GenerationAgent Skills
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
source: https://ballerina.io/security-policy/
provider: Ballerina
providerId: ballerina
description: >-
  Ballerina publishes a full vulnerability disclosure policy on its own site, with a dedicated
  reporting address, a PGP key for encrypted reports, a stated acknowledgement window and a
  reward/acknowledgement program run by WSO2. It is not mirrored to /.well-known/security.txt
  (probed 404 on ballerina.io, 2026-09-04), so the policy is discoverable by humans and not by
  machines.
program:
  published: true
  url: https://ballerina.io/security-policy/
  http_status: 200
  contact: security@ballerina.io
  pgp:
    fingerprint: AC48 3C56 C0A0 6020 4BBE F3E4 182F 3F21 255F CCE9
    keyserver: https://keys.openpgp.org
  acknowledgement_window: 24 hours
  process:
    - Private report to security@ballerina.io, encrypted with the published PGP key if desired.
    - Acknowledgement within 24 hours, followed by a detailed response and next steps.
    - Confirmation of true positives, fix development, and an immediate release where warranted.
    - Public disclosure only after mitigation; reporters are asked not to disclose before then.
  bounty:
    exists: true
    name: WSO2 Security Reward and Acknowledgement Program
    scope:
      - compiler
      - runtime
      - CLI tooling
      - standard library
      - VS Code extension
      - website
    note: Recognition/reward program run by WSO2 rather than a HackerOne/Bugcrowd-hosted bounty.
  advisories:
    location: GitHub security advisories on the ballerina-platform repositories
    example: CVE-2021-32700
well_known_security_txt: false
gaps:
  - >-
    A three-line /.well-known/security.txt on ballerina.io (Contact, Encryption, Policy) would
    make this existing policy machine-readable at zero content cost.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ballerina-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.