Porsche · Vulnerability Disclosure

Porsche Vulnerability Disclosure

Vulnerability disclosure

Porsche runs two distinct vulnerability-disclosure channels: a corporate one advertised through RFC 9116 security.txt on porsche.com, and a repository-scoped one for the Porsche Design System that uses GitHub private vulnerability reporting and publishes response-time targets and a safe-harbor clause. No public bug bounty program (HackerOne, Bugcrowd, Intigriti) was found.

Porsche runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AutomobilesCarsVehiclesAutomotiveConnected CarIdentityOpenID ConnectDesign SystemOpen-SourceGermany
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
mailto:security@porsche.de
Contact
mailto:vulnerability@porsche.de

Source

Vulnerability Disclosure

porsche-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-27'
method: searched
probe: true
source: https://www.porsche.com/.well-known/security.txt
provider: Porsche
providerId: porsche
description: >-
  Porsche runs two distinct vulnerability-disclosure channels: a corporate one advertised
  through RFC 9116 security.txt on porsche.com, and a repository-scoped one for the Porsche
  Design System that uses GitHub private vulnerability reporting and publishes response-time
  targets and a safe-harbor clause. No public bug bounty program (HackerOne, Bugcrowd,
  Intigriti) was found.
policy:
  - https://www.porsche.com/international/information-security/
  - https://github.com/porsche-design-system/porsche-design-system/blob/main/SECURITY.md
contact:
  - mailto:security@porsche.de
  - mailto:vulnerability@porsche.de
security_txt:
  - host: www.porsche.com
    url: https://www.porsche.com/.well-known/security.txt
    status: 200
    file: well-known/porsche-security.txt
    canonical: https://porsche.com/.well-known/security.txt
    contact: mailto:security@porsche.de
    expires: '2027-03-31T22:59:00.000Z'
    expired: false
    preferred_languages: [en, de]
    policy: https://www.porsche.com/international/information-security/
    hiring: https://www.porsche.com/international/aboutporsche/jobs/
  - host: identity.porsche.com
    url: https://identity.porsche.com/.well-known/security.txt
    status: 200
    file: well-known/porsche-identity-security.txt
    contact: mailto:vulnerability@porsche.de
    expires: '2025-12-31T23:59:00.000Z'
    expired: true
    expired_note: >-
      This copy's Expires field is nearly eight months in the past as of the probe date.
      RFC 9116 says a security.txt past its Expires value SHOULD NOT be used. The corporate
      copy is current; the identity host's copy needs a refresh, and it names a different
      contact address than the corporate one.
    encryption: https://assets-v2.porsche.com/int/-/media/Project/PCOM/Europe/International/Information-Security/SMIME-certificate
    preferred_languages: [en, de]
    policy: https://www.porsche.com/international/information-security/
coordinated_disclosure:
  - scope: Porsche Design System (github.com/porsche-design-system/porsche-design-system)
    mechanism: GitHub private vulnerability reporting (security advisories)
    url: https://github.com/porsche-design-system/porsche-design-system/security/advisories/new
    languages: [English, German]
    last_updated: '2026-04-30'
    response_targets:
      acknowledgement: within 5 business days
      triage: within 10 business days
      fix_critical: within 30 days
      fix_high: within 60 days
      public_disclosure: after a fix is released and consumers have had reasonable time to update
    cve_assignment: stated where applicable
    safe_harbor: true
    safe_harbor_terms:
      - good-faith effort to avoid privacy violations, data destruction and service disruption
      - only interact with accounts you own or have explicit permission to access
      - report promptly through the stated channel
      - do not exploit beyond what is necessary to demonstrate the issue
      - allow reasonable time to respond before public disclosure
    in_scope:
      - packages/** source in the repository
      - published npm packages under '@porsche-design-system/*'
      - build and release pipelines (.github/workflows, .github/actions)
      - assets served from the official Porsche CDN originating from this repo
      - the official storefront at https://designsystem.porsche.com
    out_of_scope:
      - unofficial forks, mirrors or repackaged distributions
      - third-party-hosted demos and sandboxes using snapshots of the code
      - vulnerabilities exclusively affecting unsupported versions (< 4.0)
      - upstream dependency issues
      - best-practice findings without a concrete attack scenario
      - social engineering, physical attacks, or attacks on Porsche AG infrastructure unrelated to this repository
bug_bounty:
  published: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: No public bounty program found; disclosure is coordinated by email and GitHub advisory only.
evidence:
  - url: https://www.porsche.com/.well-known/security.txt
    status: 200
    kind: security.txt (live probe)
  - url: https://identity.porsche.com/.well-known/security.txt
    status: 200
    kind: security.txt (live probe, EXPIRED)
  - url: https://raw.githubusercontent.com/porsche-design-system/porsche-design-system/main/SECURITY.md
    status: 200
    kind: repository security policy
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/porsche-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.