You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please, **do not report security vulnerabilities as GitHub issues**.
228
+
229
+
### Handling security vulnerabilities
230
+
231
+
The security team will evaluate the report and will contact the reporter to discuss the issue.
232
+
If the issue is confirmed, the security team will work with the development team to fix the issue.
233
+
The security team will evaluate the severity of the issue and will decide if the issue should be kept private until a fix is available.
234
+
235
+
This is the process:
236
+
1. open a draft security advisory on GitHub
237
+
2. assign the issue to the development team
238
+
3. the development team will work on the fix
239
+
4. the security team will review the fix
240
+
5. the fix will be released as soon as possible and announced to the users using community channels; the fix usually includes new packages along with a new image
241
+
6. depending on the severity of the issue, the development team will decide how long to wait before a full disclosure, usually between 15 and 30 days, to give
242
+
users time to update their systems.
243
+
244
+
The disclosure will be be done by publishing the security advisory on GitHub and eventually by updating the community channels
0 commit comments