Skip to content

Security: buildbuddy-io/buildbuddy

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x

Reporting a Vulnerability

Safety and data security is of utmost priority for the BuildBuddy community. If you are a security researcher and have discovered a security vulnerability in our code base, we appreciate your help in disclosing it to us in a responsible manner.

  1. Please contact us to report any security vulnerabilities found in our community development server, any of the open source code bases maintained by BuildBuddy, or any of our commercial offerings.
  2. Please refrain from requesting compensation for reporting vulnerabilities.
  3. We will acknowledge receipt of your vulnerability report and send you regular updates about our progress.
  4. If your report is reproducible as an exploit and results in a change to the code base or documentation of a BuildBuddy product, we will–at your option–publicly acknowledge your responsible disclosure.
  5. After a fix is made, we ask security researchers to wait 30 days after a release before announcing the specific details of a vulnerability, and to provide BuildBuddy with a link to any such announcements. In releases containing security fixes, BuildBuddy announces an update is available, acknowledges the contributions of security researches, and it withholds specific details until 30 days after availability to give time for the community to apply updates.

For more information, see BuildBuddy's Responsible Disclosure Policy

There aren’t any published security advisories