Woodpecker CI · Vulnerability Disclosure

Woodpecker Ci Vulnerability Disclosure

Vulnerability disclosure

Woodpecker CI runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyContinuous IntegrationContinuous DeliveryDevOpsDeveloper ToolsOpen-SourcePipelinesSelf-HostedBuild AutomationContainers
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@woodpecker-ci.org
Contact
methodprivate email
Contact
public_issues_permittedfalse

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: https://github.com/woodpecker-ci/.github/blob/main/SECURITY.md
published: true
policy_url: https://github.com/woodpecker-ci/.github/blob/main/SECURITY.md
raw_source: https://raw.githubusercontent.com/woodpecker-ci/.github/main/SECURITY.md
http_status: 200
probed: '2026-08-27'
contact:
  email: security@woodpecker-ci.org
  method: private email
  public_issues_permitted: false
policy_text_summary: >-
  "We take security seriously. If you discover a security issue, please bring it to our
  attention right away. Please DO NOT file a public issue, instead send your report
  privately to security@woodpecker-ci.org. Security reports are greatly appreciated, and
  we will publicly thank you for it. If you choose to remain anonymous, we will respect
  your request and keep your name confidential."
recognition:
  offered: true
  form: public thanks, with the option to remain anonymous
bug_bounty:
  program: none
  platforms_checked:
  - hackerone
  - bugcrowd
  - intigriti
  note: No bug bounty program was found on any platform.
security_txt:
  served: false
  probed:
  - url: https://woodpecker-ci.org/.well-known/security.txt
    status: 404
  - url: https://ci.woodpecker-ci.org/.well-known/security.txt
    status: 200
    result: miss
    note: SPA catch-all returned HTML, not an RFC 9116 document.
  checked: '2026-08-27'
  gap: >-
    The disclosure policy exists and names a dedicated security@ address, but it is only
    discoverable on GitHub. Publishing the same two facts as
    https://woodpecker-ci.org/.well-known/security.txt would make it machine-discoverable
    at no cost.
advisories:
  channel: GitHub Security Advisories on woodpecker-ci/woodpecker
  changelog_section: >-
    Each release changelog carries a dedicated "🔒 Security" section — 3.18.0 (2026-08-24)
    lists five security-relevant changes.
  url: https://github.com/woodpecker-ci/woodpecker/security/advisories

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/woodpecker-ci-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.