File tree Expand file tree Collapse file tree 1 file changed +23
-0
lines changed Expand file tree Collapse file tree 1 file changed +23
-0
lines changed Original file line number Diff line number Diff line change 1+ # Security Issue Policy
2+
3+ If you uncover a security issue with versionize_derive, please write to us on
4+ 5+
6+ Once the Firecracker [ maintainers] ( MAINTAINERS.md ) become aware (or are made
7+ aware) of a security issue, they will immediately assess it. Based on impact
8+ and complexity, they will determine an embargo period (if externally reported,
9+ the period will be agreed upon with the external party).
10+
11+ During the embargo period, maintainers will prioritize developing a fix over
12+ other activities. Within this period, maintainers may also notify a limited
13+ number of trusted parties via a pre-disclosure list, providing them with
14+ technical information, a risk assessment, and early access to a fix.
15+
16+ The external customers are included in this group based on the scale of their
17+ versionize_derive usage in production. The pre-disclosure list may also contain
18+ significant external security contributors that can join the effort to fix the
19+ issue during the embargo period.
20+
21+ At the end of the embargo period, maintainers will publicly release information
22+ about the security issue together with the versionize_derive patches that
23+ mitigate it.
You can’t perform that action at this time.
0 commit comments