Skip to content
This repository has been archived by the owner on Apr 29, 2024. It is now read-only.

Latest commit

 

History

History
46 lines (29 loc) · 1.62 KB

SECURITY.md

File metadata and controls

46 lines (29 loc) · 1.62 KB

Security Policy

At CAOS we are extremely grateful for security aware people that disclose vulnerabilities to us and the open source community. All reports will be investigated by our team.

Supported Versions

The following version support applies

Version Supported
5.x.x
4.x.x
3.x.x
2.x.x
1.x.x
0.x.x

Reporting a vulnerability

To file a incident, please disclose by email to security@caos.ch with the security details.

At the moment GPG encryption is no yet supported, however you may sign your message at will.

When should I report a vulnerability

  • You think you discovered a ...
    • ... potential security vulnerability in orbos
    • ... vulnerability in another project that orbos bases on
  • For projects with their own vulnerability reporting and disclosure process, please report it directly there

When should I NOT report a vulnerability

  • You need help applying security related updates
  • Your issue is not security related

Security Vulnerability Response

TBD

Public Disclosure

All accepted and mitigated vulnerabilitys will be published on the Github Security Page

Timing

We think it is crucial to publish advisories ASAP as mitigations are ready. But due to the unknown nature of the discloures the time frame can range from 7 to 90 days.