This project is supported under the Linux Foundation CRA stewardship framework, as described at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through the mechanisms described below, which we will coordinate with our CRA steward. For actively exploited vulnerabilities and severe incidents that may require CRA escalation, please use the project's emergency security reporting mechanisms as appropriate.
The DNA Technical Steering Committee (TSC) takes security seriously. Please report vulnerabilities privately so maintainers can investigate and prepare a fix before the issue is public.
Report a vulnerability using one of the following private channels:
- Preferred: GitHub private vulnerability reporting at https://github.com/AcademySoftwareFoundation/dna/security/advisories/new
- Email: spadjv@gmail.com (TSC members and ASWF project management only)
Do not file a public GitHub issue, pull request, or Slack message for an unfixed security vulnerability.
Include reproduction steps, affected versions or commits, and any other information that would help an investigation.
- We will acknowledge receipt of a vulnerability report within 14 days.
- We will work to assess the report promptly and, for confirmed issues that affect released software, prepare a fix as quickly as practical.
- After a fix is released, we will publish a GitHub Security Advisory (and request a CVE when appropriate).
None at this time.
Addressed vulnerabilities will be listed here with affected and patched versions, and linked from the corresponding release notes.