Skip to content

Security: veraison/docs

Security

security.md

Security Policy

The following is the default security policy for all repos within the Veraison organisation. Some repos may have a distinct security policy that overrides this policy, so please check the security tab for any repo of interest.

Supported Versions

Veraison repos operate on either a monthly, snapshot or a feature release basis. If there are no explicit stable releases, we only support the latest version.

Reporting a Vulnerability

The Veraison team is very grateful for reports of any suspected security vulnerabilities in any of the components. Please submit a security advisory via GitHub for the repository in question. If you are unsure which repository to submit to, please submit it here: https://github.com/veraison/services/security/advisories. Alternatively you can also report the issue to the security list at veraisonproject@arm.com, providing details of the problem (GitHub is preferred). The Veraison project would like to thank Arm for providing the email address, even though the project is not managed by Arm.

If possible, please include an outline of the vulnerability and the steps required to reproduce it (if applicable), as well as any information on the current release or tag maintained by the repository. If you used automated tools to identify the vulnerability, please acknowledge this and provide a minimal reproducible example to help us confirm the finding.

All reports will be thoroughly investigated by a core team. This team will communicate with the reporter of any issue to clarify any information required and to report progress of the investigation. When the investigation is complete and it is determined that a fix or workaround is required, this will be published disclosing the vulnerability and crediting the reporter for their contribution (unless they would prefer to remain anonymous).

Disclosures

Vulnerability disclosures are published in the repository's security-advisories. The disclosures will contain an overview and a fix for the vulnerability, which is usually an update. If available, they also contain a workaround.

Disclosures will be published promptly after the release of software which fixed the vulnerability.

There aren't any published security advisories