Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add website page about secutity/CVEs #781

Merged
merged 1 commit into from
Apr 15, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
1 change: 1 addition & 0 deletions src/site/markdown/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ Various documentation is available:
* The [Javadoc](apidocs/index.html)
* The list of [FAQ](faq.html)s.
* The [change notes](changes-report.html) for each release
* The [security](security.html) issues page
* The [GitHub](https://github.com/JodaOrg/joda-time) source repository


Expand Down
26 changes: 26 additions & 0 deletions src/site/markdown/security.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
## Joda-Time Security

### Security Policy

**Supported Versions**

If a security issue occurs, only the latest version is guaranteed to be patched.

**Reporting a Vulnerability**

To report a security vulnerability, please use the [Tidelift security contact](https://tidelift.com/security).
Tidelift will coordinate the fix and disclosure.


### CVEs

**[CVE-2024-23080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23080)**

This was raised publicly on 2024-04-10.
There was no prior warning or private disclosure.

The CVE is nonsense. It was raised by an AI-driven bot.
The CVE describes that a `NullPointerException` is thrown when `null` is passed into a method.
As any Java developer knows, this is perfectly normal and not a security issue or CVE.

Users of Joda-Time do not need to take any action as the CVE is invalid.
1 change: 1 addition & 0 deletions src/site/site.xml
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,7 @@
<item name="Release notes" href="changes-report.html"/>
<item name="Old release notes" href="installation.html"/>
<item name="Dependency info" href="dependency-info.html"/>
<item name="Security" href="security.html"/>
<item name="Download" href="download.html"/>
</menu>

Expand Down