| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via email to: security@spooled.cloud
Include the following information:
- Type of vulnerability (e.g., authentication bypass, injection, etc.)
- Full paths of source file(s) related to the vulnerability
- Location of the affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact assessment
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 1 week
- Fix Timeline: Depends on severity, typically 30-90 days
- Public Disclosure: After fix is released and users have time to update
- Confirmation that we received your report
- Assessment of the vulnerability and its impact
- A plan for addressing the vulnerability
- Credit in the security advisory (if desired)
We currently do not have a formal bug bounty program, but we deeply appreciate responsible disclosure and will acknowledge contributors in our security advisories.
When using the Spooled Go SDK:
- Protect your API keys: Never commit API keys to version control
- Use environment variables: Store credentials in environment variables
- Rotate keys regularly: Periodically rotate API keys
- Use minimal permissions: Create API keys with only necessary permissions
- Keep updated: Always use the latest SDK version
// Good: Use environment variables
client, err := spooled.NewClient(
spooled.WithAPIKey(os.Getenv("SPOOLED_API_KEY")),
)
// Bad: Hardcoded credentials
client, err := spooled.NewClient(
spooled.WithAPIKey("sp_live_xxxxx"), // DON'T DO THIS
)The SDK includes several security features:
- Secure cloud defaults: REST, WebSocket, SSE, and gRPC cloud endpoints use HTTPS/WSS/TLS by default; explicitly configured local/self-hosted endpoints may use plaintext
- Automatic token refresh: Refresh-token clients renew JWTs automatically, and realtime API-key clients cache and refresh their exchanged JWT near expiry
- Authenticated requests: REST/gRPC requests use API-key or bearer-token authentication; this is not cryptographic request signing
- Credential-safe logging: Built-in debug output redacts authentication headers and realtime JWT query parameters