Ballerina · Vulnerability Disclosure
Ballerina Vulnerability Disclosure
Vulnerability disclosure
Ballerina publishes a full vulnerability disclosure policy on its own site, with a dedicated reporting address, a PGP key for encrypted reports, a stated acknowledgement window and a reward/acknowledgement program run by WSO2. It is not mirrored to /.well-known/security.txt (probed 404 on ballerina.io, 2026-09-04), so the policy is discoverable by humans and not by machines.
Ballerina runs a coordinated vulnerability disclosure program on Hackerone.
IntegrationOrchestrationsOpen-SourceProgramming LanguagePackage RegistryDeveloper ToolsCode GenerationAgent Skills
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.