vulns.co
/
GKData.io MCP

Intigriti · 1 min read

Grafana Labs - Vulnerability Disclosure Program (VDP)

Vulnerability Disclosure

Open current program Reviewed policy

What this record establishes

Reviewed policy

An individually reviewed public policy is linked to this program page.

Read the reviewed policy profile →

Directory page 1 explicitly labels this Responsible disclosure; full program policy not reviewed; no active/paused status shown.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 11 published rows
AssetTypeGroup / eligibility
https://github.com/grafana/grafanaSource codeTier 1
Non-Core Grafana PluginsOtherTier 1
https://github.com/grafana/alloySource codeTier 1
https://github.com/grafana/faro-web-sdkSource codeTier 1
https://github.com/grafana/k6Source codeTier 1
https://github.com/grafana/beylaSource codeTier 1
https://github.com/grafana/pyroscopeSource codeTier 1
https://github.com/grafana/lokiSource codeTier 1
https://github.com/grafana/mimirSource codeTier 1
https://github.com/grafana/tempoSource codeTier 1
https://github.com/grafana/*WildcardTier 2
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Capture limits

  • No dedicated announcement archive or policy revision date was established.
  • Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.
  • High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03

Appears in Discovery, Profile. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software