Report a vulnerability
Bobine is an open-source project maintained independently. If you believe you found a flaw in the website, the Tor mirror, the APT repository or the software, here is how to report it and what to expect.
Last updated: 8 October 2026
1. How to report
Write to [email protected], or open a private vulnerability report on GitHub: https://github.com/FantasmaGlad/Bobine/security/advisories/new. The private GitHub report is preferable for anything exploitable: only the maintainers can see it.
We ask that any report containing exploitable details be encrypted. Our OpenPGP public key for receiving reports (Ed25519 and Curve25519, expires October 2028) has the fingerprint 23CA D324 C507 FB0F 97E6 AECA 6E4C 020E F8BD FEB2. Download it at https://bobine.fit/.well-known/security.asc or let your client discover it: gpg --locate-keys [email protected]. Check the fingerprint before sending.
The /.well-known/security.txt file is signed with this key: curl -s https://bobine.fit/.well-known/security.txt | gpg --verify. The fingerprint is also published independently in the official software repository (github.com/FantasmaGlad/Bobine/SECURITY.md and docs/security folder), on the dedicated security.bobine.fit site (hosted separately) and in the DNS (openpgp4fpr TXT and OPENPGPKEY records): check that it matches on at least two channels before sending a report.
Create your own key pair and attach your public key to your message (or tell us where to fetch it): we will reply encrypted to it. Example: gpg --quick-generate-key "Your Name <[email protected]>" future-default default 2y then gpg --armor --export [email protected]. Never share your private key.
If you cannot use PGP, use the private GitHub report rather than plain email. The /.well-known/security.txt file describes these channels in a machine-readable form (RFC 9116).
Please include: the affected address or component, steps to reproduce, the impact you observe and, if possible, a minimal proof of concept.
2. Scope
In scope:
- the bobine.fit website and its server routes (Baamix assistant, catalog);
- the Tor mirror of the site and of the APT repository;
- the apt.bobine.fit package repository and its signing chain;
- the Bobine software (github.com/FantasmaGlad/Bobine) and its installers (install.sh, install-tor.sh, Windows, macOS, Linux and Android packages).
3. Out of scope
Please do not report:
- flaws in third-party services (Vercel, Cloudflare, GitHub, Amazon, AliExpress, Hugging Face, OpenRouter, Resend): contact their vendors directly;
- social engineering, phishing, physical access;
- denial-of-service attacks, load tests and mass automated scans;
- findings without demonstrable impact (a missing non-exploitable header, displayed version, deliberately public files such as llms.txt or robots.txt);
- content or translation errors (use the usual contact address).
4. What we do
We aim to acknowledge a report within 7 days and keep you informed of progress. As the project has a single maintainer, these timings are a goal, not a contractual commitment.
We ask for a reasonable time to fix before any disclosure: 90 days by default, extendable by mutual agreement or shortened if the flaw is already being exploited. Fixes are published in the release notes and we credit reporters who wish it.
5. Good-faith research
Research carried out in good faith within the scope above will not lead to any action from us. In return: do not access other people's data beyond what is strictly needed to demonstrate the flaw, do not modify or destroy data, do not disrupt the service, do not install persistence, and do not disclose anything before it is fixed.
There is no financial reward program (bug bounty).
6. Verifying the authenticity of downloads
The APT repository is signed. Primary key fingerprint: B77D 96D7 2F84 F36A CAA3 F872 9CBF 497D 829E E15A. The install-tor.sh script pins this fingerprint and stops if it differs. This signing key is separate from the key used to receive reports (section 1). Automatic updates verify the SHA-256 digest of the files published on GitHub Releases.
7. Acknowledgments
No report has been published so far. People who report a fixed flaw will be listed here, with their consent.
8. Key and document history
7 October 2026: policy published with a first report key (fingerprint 8208 FFD3 F7AB 4DD3 6B0A CDD8 4726 A378 F683 265A).
7 October 2026: this first key is revoked and removed the same day, a few hours after publication, because its passphrase could not be used. No report had been received and the private key was never exposed. The revoked public key, carrying its revocation signature, is published in the official software repository.
7 October 2026: current key created and published (23CA D324 C507 FB0F 97E6 AECA 6E4C 020E F8BD FEB2); security.txt signed with this key.
8 October 2026: dedicated disclosure site security.bobine.fit published and fingerprint added to the DNS of bobine.fit; a daily check verifies that every channel serves the same fingerprint.
Any change of key, fingerprint or commitment is recorded here.
