If you find a security issue in Binions, please report it privately so it can be fixed before anyone can exploit it. Binions is currently in alpha, and there is no public bug-bounty programme yet — but we take security reports seriously and welcome responsible disclosure from the people who run the platform.
Responsible disclosure, in one line. Tell us privately, give us enough detail to reproduce the issue, and allow a reasonable time for a fix before sharing it publicly.
Send security reports through one of the private channels below — not as a public post, forum thread, or social-media message:
Either route reaches the people who maintain Binions. Please mark the message clearly as a security report so it is handled with the right priority.
Please don’t post it publicly first. Opening a public issue, a forum question, or a social-media thread about an unfixed vulnerability puts every other Binions user at risk. Report it privately and give us a chance to ship a fix.
A good report lets us confirm and fix the issue quickly. Please include as much of the following as you can:
You can read the version of any daemon straight from its package, which is handy to quote in a report:
dpkg-query --show --showformat='${Version}\n' binions-logger
binions-cliconsole status
Tip. If the issue shows up in the logs, the structured event records under
/var/log/binions/— queried by theircorrelation_id— often contain exactly the trace a fix needs. Attach the relevant excerpts.
Once a report reaches us, we work to confirm the issue, develop a fix, and ship it as part of a normal package update. A couple of things to set expectations:
apt upgrade to receive them.No advisories yet. Because Binions is pre-1.0 alpha, no security advisories or CVEs have been published to date. When that changes, security-relevant fixes will be called out in the release notes. See CVE / security advisories for how this will work.