Skip to content

Security: AcademySoftwareFoundation/dna

SECURITY.md

CRA stewardship

This project is supported under the Linux Foundation CRA stewardship framework, as described at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through the mechanisms described below, which we will coordinate with our CRA steward. For actively exploited vulnerabilities and severe incidents that may require CRA escalation, please use the project's emergency security reporting mechanisms as appropriate.

Security Policy

The DNA Technical Steering Committee (TSC) takes security seriously. Please report vulnerabilities privately so maintainers can investigate and prepare a fix before the issue is public.

Security contacts

Report a vulnerability using one of the following private channels:

  1. Preferred: GitHub private vulnerability reporting at https://github.com/AcademySoftwareFoundation/dna/security/advisories/new
  2. Email: spadjv@gmail.com (TSC members and ASWF project management only)

Do not file a public GitHub issue, pull request, or Slack message for an unfixed security vulnerability.

Include reproduction steps, affected versions or commits, and any other information that would help an investigation.

Response expectations

  • We will acknowledge receipt of a vulnerability report within 14 days.
  • We will work to assess the report promptly and, for confirmed issues that affect released software, prepare a fix as quickly as practical.
  • After a fix is released, we will publish a GitHub Security Advisory (and request a CVE when appropriate).

Known vulnerabilities

None at this time.

Addressed vulnerabilities will be listed here with affected and patched versions, and linked from the corresponding release notes.

There aren't any published security advisories