Skip to content

Latest commit

 

History

History
35 lines (22 loc) · 1.3 KB

SECURITY.md

File metadata and controls

35 lines (22 loc) · 1.3 KB

Security Policy


Reporting a Vulnerability

The flexo team and IBM take security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings.

To report a security issue, please open a draft security advisory by visiting: https://github.com/ibm/flexo/security/advisories/new

Please DO NOT file a public issue for security vulnerabilities.

Vulnerability Management Process

  1. Once you submit a vulnerability report, it will be reviewed within 5 business days
  2. We will acknowledge your report and provide an initial assessment
  3. We will work on reproducing and validating the issue
  4. Once validated, we will develop and test a fix
  5. A security advisory will be published and the fix will be released
  6. Credit will be given to the reporter (unless anonymity is requested)

Supported Versions

We provide security updates for the latest minor version of the most recent major version.

Security Update Process

Security fixes will be released as:

  • Patch releases for critical vulnerabilities
  • Part of regular releases for non-critical issues

Third Party Dependencies

We use automated dependency scanning to identify known vulnerabilities in our dependencies. Users should ensure they are using the latest compatible versions of all dependencies when deploying the project.