Skip to content

Security: linux-nvme/ci-containers

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Please send an email to:

Daniel Wagner wagi@kernel.org

Include as much information as possible to help us understand and reproduce the issue, such as:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fixes (if available)

Disclosure Policy

We ask that security issues are not disclosed publicly until they have been investigated and a fix has been prepared.

After receiving a report, we will:

  1. Acknowledge receipt of the vulnerability report.
  2. Investigate and determine the impact.
  3. Develop and test a fix where applicable.
  4. Coordinate responsible disclosure.

Supported Versions

Security fixes are generally applied to the currently maintained version of the project. Older versions may not receive security updates.

Scope

This policy applies only to vulnerabilities in the source code of this repository. Issues related to third-party dependencies should be reported to the respective upstream projects.

Thank you for helping improve the security of this project.

There aren’t any published security advisories