Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Required] Clearly defined and discoverable process to report security issues. #149

Open
avishnu opened this issue Nov 27, 2024 · 4 comments
Assignees
Labels
Incubation-no-compliance Incubation criteria not complied
Milestone

Comments

@avishnu
Copy link
Member

avishnu commented Nov 27, 2024

No description provided.

@tiagolobocastro
Copy link
Collaborator

@tiagolobocastro
Copy link
Collaborator

Also btw the security guidelines.

@tiagolobocastro
Copy link
Collaborator

Security policy

Security bulletins

For requesting any information regarding the security of this project please join:

Reporting a vulnerability

GitHub
is the preferred method for privately reporting a security vulnerability.

  1. Fill out the form on the GitHub Security Reporting
    • You will receive a confirmation email upon submission
  2. You may be contacted by the maintainers to further discuss the reported item.
    Please bear with us as we seek to understand the breadth and scope of the
    reported problem, recreate it, and confirm if there is a vulnerability
    present.

Public Disclosure Timing

We prefer to fully disclose the bug as soon as possible once a user mitigation is available.
The Fix Lead drives the schedule using their best judgment based on severity, development time, and release manager feedback. If the Fix Lead is dealing with a Public Disclosure all timelines become ASAP.

Supported Versions

OpenEBS releases follow the semver specification.
Security fixes are typically merged to the HEAD branch and due for release on the next minor version.
Upon request or if deemed necessary as part of a critical security fix we may backport the changes as a patch release.

@tiagolobocastro
Copy link
Collaborator

How does this look?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Incubation-no-compliance Incubation criteria not complied
Projects
Status: In Progress
Development

No branches or pull requests

2 participants