Skip to content

Security: chantico-project/.github

SECURITY.md

Chantico Project Open Source Project Security Policy

This security policy applies to the open source projects under the Chantico project organization on GitHub. We are committed to maintaining a secure and trustworthy environment for our users and contributors. If you discover a security vulnerability in any of our projects, please report it to us immediately.

Note that standard disclaimers applies to all our projects. The software is provided "as is", without warranty of any kind, express or implied, as indicated in the LICENSE file of each project.

CRA stewardship

This project is supported under the Linux Foundation CRA stewardship framework, as described at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through the mechanisms described below, which we will coordinate with our CRA steward. For actively exploited vulnerabilities and severe incidents that may require CRA escalation, please use the project’s emergency security reporting mechanisms as appropriate.

Reporting Security Issues

We encourage you to report any security vulnerabilities you discover in our projects in a responsible manner, but please do not report security vulnerabilities through public GitHub issues. Please follow these steps to report a vulnerability:

  1. Test out the vulnerability in private: If you discover a potential security vulnerability, please do not disclose it publicly or attempt it on public endpoint of the Chantico project until we have had a chance to investigate and address it. This helps prevent malicious actors from exploiting the vulnerability or leaking production data before it is fixed.
  2. Clearly identify the vulnerability: Draft a clear and concise description of the vulnerability, including steps to reproduce it if possible.
  3. Contact us privately: Please report the vulnerability to us by going to the repository in which the vulnerability is primarily present, clicking the "Security and privacy" tab, and then clicking "Report a vulnerability". Alternatively, for example if you cannot sign up to GitHub, you can send us an email to chantico-project@tno.nl with the subject line "Security Vulnerability Report". In your report, include the type of issue, description of the vulnerability, the involved repository or repositories (if possible, specific modules, files and/or lines that are affected), version/tag/commit of the affected code, and any relevant details in the email (scope or impact, steps or configuration to reproduce the issue or even proof-of-concept code, risk potential and vector such as data leaks or system intrusions). The report will be treated with confidentiality and will only be shared with the necessary members of our team to investigate and address the issue.

There aren't any published security advisories