The Cedar repo is scanned frequently for code and dependency vulnerabilities. Notifications are received by the Cedar Team, who assess risk, prioritize, and determine a remediation plan. Typically this process involves a package update or patch release and is resolved as soon as possible.
If you discover a potential security issue, do let us know as soon as possible. We'll work toward a resolution as quickly as possible, so please provide us with a reasonable amount of time before disclosure to the public or a third-party.
There are two ways to contact us:
- Email [email protected], or
- Use GitHub's private Vulnerability Reporting feature (to learn how this works, click here)
Thank you for helping improve Cedar security!
We take security seriously. Which is why we offer a friendly reminder that "Cedar Framework Security" != "Security of Applications built with Cedar"
It's our responsibility (Cedar Team members) to implement security best practices and make the framework as secure as possible. We will do as much as we can; however, we can only do so much. Ultimately, security rests in the hands of the application developers who use Cedar. If you haven't already, we recommend starting the security process for your application with GitHub's Security Tools and Best Practices.