Properly add security policy (#6163)
* Create SECURITY.md * Update SECURITY.md
Chris Akritidis committed
May 29, 2019 at 17:03 UTC
a40eae5c8938c26c53507ff6c23e2eeca7e055c9
1 file changed
+43
SECURITY.md
new
+43
@@ -0,0 +1,43 @@
1
+# Security Policy
2
+
3
+## Supported Versions
4
+
5
+| Version | Supported |
6
+| ------- | ------------------ |
7
+| Latest | :white_check_mark: |
8
+
9
+## Reporting a Vulnerability
10
+
11
+We’re extremely grateful for security researchers and users that report vulnerabilities to Netdata Open Source Community. All reports are thoroughly investigated by a set of community volunteers.
12
+
13
+To make a report, please create a post [here](https://groups.google.com/a/netdata.cloud/forum/#!newtopic/security) with the vulnerability details and the details expected for [all Netdata bug reports](.github/ISSUE_TEMPLATE/bug_report.md).
14
+
15
+### When Should I Report a Vulnerability?
16
+
17
+- You think you discovered a potential security vulnerability in Netdata
18
+- You are unsure how a vulnerability affects Netdata
19
+- You think you discovered a vulnerability in another project that Netdata depends on (e.g. python, node, etc)
20
+
21
+### When Should I NOT Report a Vulnerability?
22
+
23
+- You need help tuning Netdata for security
24
+- You need help applying security related updates
25
+- Your issue is not security related
26
+
27
+### Security Vulnerability Response
28
+
29
+Each report is acknowledged and analyzed by Netdata Team members within 3 working days. This will set off a Security Release Process.
30
+
31
+Any vulnerability information shared with Netdata Team stays within Netdata project and will not be disseminated to other projects unless it is necessary to get the issue fixed.
32
+
33
+As the security issue moves from triage, to identified fix, to release planning we will keep the reporter updated.
34
+
35
+### Public Disclosure Timing
36
+
37
+A public disclosure date is negotiated by the Netdata team and the bug submitter. We prefer to fully disclose the bug as soon as possible once a user mitigation is available. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested, or for vendor coordination. The timeframe for disclosure is from immediate (especially if it's already publicly known) to a few weeks. As a basic default, we expect report date to disclosure date to be on the order of 7 days. The Netdata team holds the final say when setting a disclosure date.
38
+
39
+### Security Announcements
40
+
41
+Every time a security issue is fixed in Netdata, we immediately release a new version of it. So, to get notified of all security incidents, please subscribe to our releases on github.
42
+
43
+[]()