Skip to content

Security: thunder-id/thunderid

Security

SECURITY.md

Security Policy

ThunderID follows the OpenWallet Foundation's Security Vulnerability Disclosure Policy.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report privately using GitHub Private Vulnerability Reporting:

  1. Go to the Security Advisories page.
  2. Click Report a vulnerability to open a private draft advisory.
  3. Include as much detail as you can: affected version or commit, a description of the issue, reproduction steps, and any potential impact.

You can expect an acknowledgement of your report within 2 business days. We will keep you informed as we investigate, and we will coordinate the disclosure timeline and any credit with you.

Disclosure Process

We follow coordinated disclosure. When a report is confirmed, the security team will work on a fix privately, agree an embargo period with the reporter (not longer than 90 days), and publish a GitHub security advisory when the fix is released. CVEs are issued through GitHub Security Advisories.

Security Team

The Core Maintainers of ThunderID as defined in the MAINTAINERS.md file will be the security team. The security team is responsible for triaging and fixing security issues, coordinating with reporters, and publishing advisories. The security team will also be responsible for reviewing and approving any changes to this policy.

There aren't any published security advisories