-
Notifications
You must be signed in to change notification settings - Fork 578
Update Quickwit security policy with current vulnerability reporting guidance #6684
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+18
−10
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,15 +1,23 @@ | ||
| # Security Policy | ||
|
|
||
| ## Supported Versions | ||
| ## Vulnerability Reporting | ||
|
|
||
| | Version | Supported | | ||
| | ------- | ------------------ | | ||
| | 0.3.1 | :white_check_mark: | | ||
| | < 0.3.1 | :x: | | ||
| We deeply appreciate any effort to discover and disclose security vulnerabilities responsibly. | ||
|
|
||
| ## Reporting a Vulnerability | ||
| ### Quickwit CI | ||
|
|
||
| To disclose a vulnerability in our code, please notify us by email at security@quickwit.io or private message _@fulmicoton_ or _@guilload_ on our Discord | ||
| server ([discord.quickwit.io](https://discord.quickwit.io)). We will open a draft security advisory on our repository and grant you access so you can | ||
| share with us more details about the vulnerability. After releasing a fix, we will publish the security advisory to publicly disclose the security vulnerability | ||
| to the project's community. | ||
| If you would like to report a vulnerability in Quickwit's CI or have security concerns with other Datadog products, please email [security@datadoghq.com](mailto:security@datadoghq.com). | ||
|
|
||
| We take all disclosures seriously and will do our best to respond promptly, verify the vulnerability, and take the necessary steps to fix it. After our initial reply, we will periodically update you on the status of the fix. | ||
|
|
||
| ### Other Reports | ||
|
|
||
| Quickwit is an open source project designed to be self-hosted, so users are responsible for managing their deployments. Vulnerabilities in Quickwit deployments could potentially be exploited by malicious actors who already have access to the user's infrastructure. We encourage responsible disclosure by [opening a GitHub issue](https://github.com/quickwit-oss/quickwit/issues/new) so that risks can be properly assessed and mitigated. | ||
|
|
||
| To help us investigate your report, please include any of the following: | ||
|
|
||
| - A proof of concept | ||
| - Any tools used, including their versions | ||
| - Any relevant output | ||
|
|
||
| Do not include credentials, secrets, or other sensitive information in a public GitHub issue. | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.