Skip to content

Security: BSC-ES/providentia

Security

SECURITY.md

Security Policies and Procedures

This document outlines security procedures and general policies for the Providentia project.

Reporting Security Issues

Please do NOT report security vulnerabilities through public issues.

The Providentia maintainers take security bugs seriously. Thank you for improving the security of Providentia. We appreciate your efforts and responsible disclosure and will make every effort to acknowledge your contributions.

If you believe you have found a security vulnerability in Providentia, please report it by sending an email to [email protected], [email protected] and [email protected].

Preferred Languages

All communications should be preferably in English. Spanish and Catalan are also accepted.

Policy

When the Providentia maintainers receive a security bug report, they will assign it to a primary handler. This person will coordinate the fix and release process as follows:

  • Confirm the problem and determine the affected versions.
  • Audit code to find any potential similar problems.
  • Prepare fixes for all releases still under maintenance.
  • Cut new releases as soon as possible.

CVE's may also be issued depending on the risk level, with credit to the reporter.

There aren’t any published security advisories