|
1 | | -<!-- |
2 | | -SPDX-FileCopyrightText: 2019-2022 Alliander N.V. |
3 | | -SPDX-License-Identifier: MPL-2.0 |
4 | | ---> |
5 | | -# Security Policy |
| 1 | +[//]: # (SPDX-FileCopyrightText: 2024-2025 Copyright Contributors to the Weather Provider API project) |
6 | 2 |
|
7 | | -## Supported Versions |
| 3 | +[//]: # (SPDX-License-Identifier: MPL-2.0) |
8 | 4 |
|
9 | | -The following versions of the API and its libraries are currently being supported: |
| 5 | +# Security |
10 | 6 |
|
11 | | -| VERSION | SUPPORTED | |
12 | | -| ------- | ---------------------- | |
13 | | -| 3.0.x | :x: *(in development)* | |
14 | | -| 2.x | :white_check_mark: | |
15 | | -| < 2.0 | :x: | |
| 7 | +At Alliander, we consider the security of our systems and software a top priority. But no matter how much effort we put |
| 8 | +into system security, there can still be vulnerabilities present. |
16 | 9 |
|
17 | | -## Reporting a Vulnerability |
| 10 | +If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as |
| 11 | +possible. We would like to ask you to help us better protect our clients and our systems. |
18 | 12 |
|
19 | | -To report a vulnerability, please directly contact us at: [email protected] |
| 13 | +## Report a security issue |
20 | 14 |
|
21 | | -Upon receiving information on this vulnerability, we will aim to either immediately repair it, or issue a warning via the discussion board, depending on the ease with which it can be fixed. In both cases we will aim to solve the vulnerability as fast as possible. |
| 15 | +Use the contact details on |
| 16 | +the [Alliander.com Vulnerability Reporting page](https://www.alliander.com/en/coordinated-vulnerability-disclosure/). |
| 17 | + |
| 18 | +Please describe clearly how the issue can be reproduced, so we can fix it quickly. Typically, the IP address or URL of |
| 19 | +the affected system and a description of the vulnerability are sufficient. We may contact you if we need more |
| 20 | +information about a complex vulnerability. |
| 21 | + |
| 22 | +## Other issues |
| 23 | + |
| 24 | +For non-security related issues, please use the [issue tracker]( |
| 25 | + |
| 26 | +## Thanks |
| 27 | + |
| 28 | +We don't have a bug bounty program, but we're grateful for all the reports we get. We offer an Alliander Security hoodie |
| 29 | +as a reward for significant security problems. |
| 30 | + |
| 31 | +## List of Currently Supported Versions of the Weather Provider API |
| 32 | + |
| 33 | +| Version | Support status | |
| 34 | +|--------------|------------------------| |
| 35 | +| ***v2.x.x*** | ✓ *- Supported* | |
22 | 36 |
|
23 | | -Should a vulnerability pose an extremely high risk, we may decide to flag releases as "High Risk", and we may issue temporary releases with limited functionality, to prevent our users from being unnecessarily at risk. These events will also be advertised on the Discussions board, and these "High Risk" and "Limited Functionality" releases will be tagged as such. |
|
0 commit comments