Skip to content

Security: Tradebaas/Groundwork

SECURITY.md

Security policy

Report a vulnerability

Report security issues privately via this repository's Security tab, "Report a vulnerability" (GitHub private vulnerability reporting). Never use a public issue or pull request for a security problem.

Include what you can: affected version or commit, steps to reproduce, impact as you see it. A partial report is welcome; send what you have.

What happens next (coordinated disclosure)

  • Acknowledgement within 3 working days.
  • Assessment within 14 days: severity, affected versions, fix plan. After that you get a status update at least every 14 days.
  • Coordinated disclosure: an advisory is published when a fix is available, or 90 days after the report, whichever comes first. If more time is needed, we say so and agree a new date with you.
  • Credit in the advisory, if you want it.

Good-faith research is safe here: stay at proof-of-concept depth (no data exfiltration, no service disruption, no social engineering), leave user data alone, and give us the window above. Under those rules we will not pursue legal action.

Support period and security updates

  • Groundwork itself (the framework this repo started from) is free and open-source software that its maintainer does not monetise, so it is not made available on the market within the meaning of the CRA and carries no published support period. The scope test behind that, and what would flip it, stand in the CRA row of the regimes table. Security fixes land on main of Tradebaas/Groundwork and are named in the changelog of the release that carries them; a copied project starts from the state at copy time and receives nothing automatically, so track upstream yourself.

Security fixes ship through the normal delivery pipeline and are named in the changelog. Supported versions: the latest release, unless the line above says otherwise.

Our own reporting duties

An actively exploited vulnerability or a severe incident in a shipped product triggers the CRA Art 14 duty: early warning within 24h, notification within 72h, then a final report on the regime's own deadline, via the ENISA single reporting platform and the national CSIRT (for NL: NCSC). Current dates per regime: the regimes table. Which of them reach this project, and the status per obligation: its register.

There aren't any published security advisories