Security

Report security issues privately to support@tobupengin.com.

Do not open a public issue, pull request, or discussion for a vulnerability. A public report tells everyone running Pengin-Pi-3 about the hole at the same moment it tells us, including people who will use it. Private disclosure gives us time to fix it and gives deployers time to update.

What to report

  • Any vulnerability in Pengin-Pi-3 — authentication or permission bypass, injection, data exposure, insecure defaults in the shipped configuration
  • Credentials, keys, or private data accidentally committed to the repository
  • A security incident affecting a deployment you believe originates in the platform rather than your own configuration

If you are unsure whether something qualifies, send it. A report that turns out to be a non-issue costs us a few minutes. An unreported vulnerability costs considerably more.

How to report

Email support@tobupengin.com. Include:

  • What the issue is
  • Which version, branch, or commit you found it on
  • How to reproduce it — exact steps, and a proof of concept if you have one
  • What an attacker could do with it
  • Your assessment of severity, if you have one

Plain text is fine. We would rather have a rough report today than a polished one next week.

What happens next

Reports are ingested into Pengin Open Source's internal GitLab as private issues and worked there. The report stays private through triage and fix.

  • Acknowledgement. We confirm receipt and let you know whether we can reproduce it.
  • Triage. We assess severity and scope — whether it affects the core, the deployment configuration, or an unsupported branch.
  • Fix. Developed privately. We may contact you for clarification or to verify the fix.
  • Disclosure. Once a fix is available, the issue is described publicly in the release notes so deployers know why to update. The description covers what was wrong and what to do about it, not a working exploit.

We will credit you in the disclosure if you want that, and leave you out of it if you don't. Say which when you report.

Please do not

  • Publish details before a fix is available
  • Test against deployments you do not own
  • Access, modify, or retain data that is not yours while demonstrating an issue

A vulnerability report is welcome. Exploiting one against somebody else's running site is not research.

Scope

In scope: the main branch of Pengin-Pi-3 — the core (main/, util/, templates/) and the shipped Docker, Nginx, and Traefik configuration.

Out of scope: application branches on the public mirror, which carry no support commitment (see Info); issues in upstream dependencies, which should go to those projects; and misconfiguration of your own deployment. If you are not sure which side of that line something falls on, report it and we will tell you.

For deployers

Security reporting is separate from running the platform securely. If you operate a Pengin-Pi-3 instance, Deployment covers the configuration the platform expects, and Architecture documents what the security layer actually enforces — the blocklist middleware, rate limiting, reCAPTCHA integration, and the Nginx and Fail2ban edge setup.

There is currently no security mailing list. Watch the repository for release notes.

Alpha status

Pengin-Pi-3 is alpha software. The core is running, the edges are still moving, and the security surface has not been independently audited. If you are evaluating it for a deployment handling sensitive data, contact us first so we can tell you honestly where the sharp corners are.

Pages Here

No sub-pages yet.

Page Info

Wiki: Docs

Created on Sep 20, 2026 by Tobu Pengin, L.L.C.

Maintainers

Editor Last Activity
Tobu Pengin, L.L.C. creator Sep 20, 2026