Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Coordinated vulnerability disclosure #8652

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 14 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

The GeoNetwork community takes the security of the software and all services based on the software product seriously. On this page you can find the versions for which the community provides security patches.

If you believe you have found a security vulnerability in the software or an implementation of the software, please report it [here](https://github.com/geonetwork/core-geonetwork/security/advisories/new) as described below. Do not publish the vulnerability in any public forums (such as Twitter/X, email list or issue tracker).
If you believe you have found a security vulnerability in the software or an implementation of the software, please report it [here](https://github.com/geonetwork/core-geonetwork/security/advisories/new) as described below. Do not publish the vulnerability in any public forums (such as social media, user forum, or issue tracker).

## Supported Versions

Expand All @@ -28,3 +28,16 @@ If you encounter a security vulnerability in GeoNetwork please take care to repo
* Keep in mind that community members are volunteers and an extensive fix may require fundraising / resources

For more information see [How to contribute](https://github.com/geonetwork/core-geonetwork/wiki/How-to-contribute).

## Coordinated vulnerability disclosure

Disclosure workflow:

1. GitHub [security advisory](https://github.com/geonetwork/core-geonetwork/security) used to reserve a CVE number.
2. Vulnerability addressed and backported to "latest" and "stable" branches, allowing origional reporter to verify nightly build.
3. Fix available in published release for all "supported versions" idenitifed above, providing an oppertunity for everyone to update.
4. The CVE vulnerability is published with mitigation and patch instructions.

This approach provides everyone a chance to update prior to public disclosure.

Those seeking greater transparency are encouraged to [volunteer as a committer](CONTRIBUTING.md#core-commit-access), or work with one of the [commercial support provides](https://www.osgeo.org/service-providers/?p=geonetwork) to particiapte on your behalf.
Loading