Skip to content

Security: Obsidian-Solutions/.github

SECURITY.md

Security Policy

Supported Versions

Only the latest release is supported. Older versions do not receive security fixes.

Version Supported
Latest release Yes
Older releases No

Reporting a Vulnerability

If you have found a security vulnerability in this project, report it privately to security@obsidiansolutions.co.uk. Do not open a public issue for a security problem.

When you report a vulnerability, include:

  • the repository or component where the vulnerability can be observed
  • a brief description of the vulnerability
  • the steps needed to reproduce the vulnerability
  • non-destructive exploitation details

If you can, also include:

  • the type of vulnerability, for example an OWASP category
  • screenshots or logs that show the exploitation

Response targets

We acknowledge every report and fix confirmed vulnerabilities within the targets below. The clock starts when we confirm the vulnerability.

Severity Acknowledge Fix target
Critical 1 working day 7 days
High 2 working days 14 days
Medium 5 working days 30 days
Low 5 working days 90 days or next release

Disclosure

This project follows responsible disclosure. We aim to fix confirmed vulnerabilities before public disclosure, and we credit the reporter unless they ask to stay anonymous.

Guidelines for investigating

When you investigate a vulnerability, you must not:

  • break the law
  • access unnecessary or excessive amounts of data
  • modify data
  • use high-intensity invasive or destructive scanning tools
  • try a denial of service
  • disrupt services or systems
  • tell other people about the vulnerability before disclosure
  • social engineer, phish or physically attack staff or infrastructure
  • demand money to disclose a vulnerability

There aren't any published security advisories