spacelift-io-bug-bounty-program

6
In Scope
8
Out of Scope

In-Scope Assets (6)

AssetCategoryQuick Links
MFAOTHER-
Native K8S workers and operatorOTHER-
OIDC-based API keysOTHER-
Spacelift IntentOTHER-
https://*.app.spacelift.devURL
https://spacelift.dev/URL
Out-of-Scope Assets (8)
AssetCategory
Any communication with Spacelift colleagues.OTHER
Any other Spacelift assets not specifically listed as in-scope.OTHER
Attacks against any account other than the specified target accounts.OTHER
Bypasses of user or API key creation limits (including via race conditions or business logic issues)OTHER
Contact form (especially HubSpot ones)OTHER
Data breaches or credential dumps.OTHER
Session keeps using old user group permissions if user group permissions are changed during a given session's lifespanOTHER
Third-party companies that perform business transactions for SpaceliftOTHER