Skip to content

Security: EUDIPLO/eudiplo

SECURITY.md

Security Policy

Supported Versions

We release security patches and updates for actively maintained versions. The table below outlines supported versions:

Version Supported
Latest ✅
< Latest ❌

Reporting a Vulnerability

If you discover a potential security vulnerability in this project, please report it responsibly and privately.

Please do not disclose security vulnerabilities through public GitHub issues, discussions, or pull requests.

Preferred Reporting Channels

  1. GitHub Private Vulnerability Reporting: Submit a confidential advisory directly via GitHub Security Advisories.
  2. Email: Send a confidential email to the LF Decentralized Trust security team:

Information to Include

To help us triage and resolve the report quickly, please include as much detail as possible:

  • Type and severity of the vulnerability (for example, authentication bypass, injection, cryptographic flaw, or credential disclosure)
  • Affected package, application, and version(s)
  • Location of the affected code (tag, branch, commit, or direct file link)
  • Clear step-by-step instructions to reproduce the issue
  • Minimal proof-of-concept code or sample inputs, when appropriate
  • Potential impact and exploitation scenarios
  • Any suggested fixes or mitigations
  • Your contact information, if you would like follow-up

What to Expect

  • Initial Acknowledgment: Within 3 business days of receipt
  • Triage and Assessment: Within 10 business days, including preliminary severity assessment and reproduction verification
  • Regular Updates: We will keep you informed of our progress as remediation proceeds
  • Remediation and Patch: Fix development and testing will be prioritized based on severity
  • Coordinated Disclosure: Fixes will be released alongside a published GitHub security advisory and CVE identifier, where applicable

Vulnerability Handling Process

  1. Triage: We evaluate the severity and impact of the reported vulnerability
  2. Investigation: Our team investigates and confirms the vulnerability
  3. Fix Development: We develop and test a fix in private, when appropriate
  4. Release: We release a security update
  5. Advisory Publication: We publish a GitHub security advisory with impact, affected versions, and mitigation or upgrade steps
  6. Disclosure: We coordinate responsible disclosure with the reporter

Security Best Practices

When using this project, we recommend:

  • Keep dependencies up to date
  • Use the latest stable version
  • Follow secure coding practices
  • Regularly review security advisories
  • Implement proper authentication and authorization
  • Use HTTPS in production environments
  • Regularly backup your data

Scope

This security policy applies to:

  • The main codebase in this repository
  • Dependencies we directly maintain
  • Documentation and configuration examples

This policy does not cover:

  • Third-party dependencies (please report to their respective maintainers)
  • Issues in forked repositories
  • Social engineering attacks

Recognition

We believe in recognizing security researchers who help us maintain the security of our project. With your permission, we will:

  • Credit you in our security advisory
  • Add you to our security acknowledgments
  • Mention you in release notes (if desired)

Contact Information

For security-related questions or concerns, please contact:

Thank you for helping keep our project and community safe!

Learn more about advisories related to EUDIPLO/eudiplo in the GitHub Advisory Database