UK Power Networks · Vulnerability Disclosure

Uk Power Networks Vulnerability Disclosure

Vulnerability disclosure

UK Power Networks runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyUnited KingdomUtilitiesElectricityGridDistribution NetworkOpen DataSmart MeteringDEREV ChargingCarbonEnergy Markets
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@opendatasoft.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-06-20'
method: searched
probe: true
source: >-
  Live fetch of https://ukpowernetworks.opendatasoft.com/.well-known/security.txt (HTTP 200) and
  https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md (HTTP 200). Probed 2026-07-27.
summary: >-
  A disclosure route exists for both halves of this estate, but neither is UK Power Networks'
  own named security programme. The API host serves an RFC 9116 security.txt whose contact is the
  platform vendor's (security@opendatasoft.com), and the official SDK repository ships a SECURITY.md
  with a responsible-disclosure policy that tells reporters to email "the UK Power Networks team"
  without naming an address. UK Power Networks publishes no bug bounty, no dedicated vulnerability
  disclosure page for the Open Data Portal, and no security contact of its own that was reachable
  anonymously — the corporate host www.ukpowernetworks.co.uk returns HTTP 403 to anonymous
  non-browser requests, so absence there is unproven rather than confirmed.
policy:
- https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md
contact:
- mailto:security@opendatasoft.com
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  result: none found
security_txt:
  url: https://ukpowernetworks.opendatasoft.com/.well-known/security.txt
  http_status: 200
  file: well-known/uk-power-networks-security.txt
  fields:
    Contact: mailto:security@opendatasoft.com
    Expires: '2050-01-01T11:00:00.000Z'
    Preferred-Languages: en,fr
  policy_field: absent
  owner: Opendatasoft (the platform vendor), not UK Power Networks
  rfc9116: true
  note: >-
    The Expires value is set 24 years out, which defeats the point of the field — RFC 9116 expects a
    date under a year so stale files are detectable. Recorded as observed.
sdk_policy:
  url: https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md
  http_status: 200
  scope: the ukpyn Python client, not the API
  reporting:
    channel: email
    address_published: false
    instruction: Do not open a public GitHub issue; email the UK Power Networks team with details.
    required_content: [description, steps to reproduce, potential impact, suggested fixes (optional)]
    acknowledgement_target: 48 hours
  supported_versions: latest only
  practices_published:
  - No real API keys or secrets in the repository; environment variables for all sensitive configuration
  - .env gitignored and never committed
  - Placeholder values only in tests, examples and documentation
  - Automated dependency scanning and prompt patching
  - Input validation on user-supplied data
  - Pinned GitHub Action commit SHAs for CodeQL compliance (per the changelog)
gaps:
- No UK Power Networks security contact address is published anywhere reachable anonymously.
- The security.txt on the API host names the platform vendor, so a report about UK Power Networks data would land with Opendatasoft.
- No Policy field in security.txt, so there is no machine-discoverable disclosure policy URL.
- No coordinated disclosure timeline or safe-harbour statement.
evidence:
- source: well-known/uk-power-networks-security.txt
  kind: security.txt
  http_status: 200
  fetched: '2026-07-27'
- source: https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md
  kind: repository security policy
  http_status: 200
  fetched: '2026-07-27'
- source: https://www.ukpowernetworks.co.uk/.well-known/security.txt
  kind: corporate host probe
  http_status: 403
  fetched: '2026-07-27'
  note: Akamai edge block; absence not confirmed.
related:
  well_known: well-known/uk-power-networks-well-known.yml
  domain_security: security/uk-power-networks-domain-security.yml