Skip to content

Security: svt/encore

Security

SECURITY.md

Security Reporting

If you wish to report a security vulnerability but not in a public issue -- thank you! -- we ask that you follow the following process.

Please report security vulnerabilities by filling out the following template:

  • PROJECT: A URL to the project repository
  • PUBLIC: Please let us know if this vulnerability has been made or discussed publicly already, and if so, please let us know where.
  • DESCRIPTION: Please provide precise description of the security vulnerability you have found with as much information as you are able and willing to provide.

Please send the above info, along with any other information you feel is pertinent to: opensource-security@svt.se.
Public PGP-key

Vulnerabilities reported will be handled on a best effort basis.

In addition, you may request that the project provide you a patched release in advance of the release announcement, however, we can not guarantee that such information will be provided to you in advance of the public release and announcement.

However, the Open Source Team will email you at the same time any public announcement is made. The Open Source Team will let you know within a few weeks whether or not your report has been accepted or rejected. We ask that you please keep the report confidential until we have made a public announcement.

There aren’t any published security advisories