@cryptotaxi247 / netdata-1 / commits / f86173d6c

Update security policy (#6166)

* Move Security and Disclosure Info to make it more visible * Remove docs/Netdata-Security-and-Disclosure-Information.md, replace it with SECURITY.md * white_check_mark not supported in HTML generation

Chris Akritidis committed May 29, 2019 at 17:27 UTC f86173d6c7547f4bd7841a0a3589a2e1ea703ba0
3 files changed +2 -41
SECURITY.md
+1 -1
@@ -4,7 +4,7 @@
4
5 | Version | Supported |
6 | ------- | ------------------ |
7 -| Latest | :white_check_mark: |
7 +| Latest | Yes |
8
9 ## Reporting a Vulnerability
10
docs/Netdata-Security-and-Disclosure-Information.md deleted
-39
@@ -1,39 +0,0 @@
1 -# Netdata Security and Disclosure Information
2 -
3 -This page describes Netdata security and disclosure information.
4 -
5 -## Security Announcements
6 -
7 -Every time a security issue is fixed in Netdata, we immediately release a new version of it. So, to get notified of all security incidents, please subscribe to our releases on github.
8 -
9 -## Report a Vulnerability
10 -
11 -We’re extremely grateful for security researchers and users that report vulnerabilities to Netdata Open Source Community. All reports are thoroughly investigated by a set of community volunteers.
12 -
13 -To make a report, please email the private [security@netdata.cloud](mailto:security@netdata.cloud) list with the security details and the details expected for [all Netdata bug reports](../.github/ISSUE_TEMPLATE/bug_report.md).
14 -
15 -## When Should I Report a Vulnerability?
16 -
17 -- You think you discovered a potential security vulnerability in Netdata
18 -- You are unsure how a vulnerability affects Netdata
19 -- You think you discovered a vulnerability in another project that Netdata depends on (e.g. python, node, etc)
20 -
21 -### When Should I NOT Report a Vulnerability?
22 -
23 -- You need help tuning Netdata for security
24 -- You need help applying security related updates
25 -- Your issue is not security related
26 -
27 -## Security Vulnerability Response
28 -
29 -Each report is acknowledged and analyzed by Netdata Team members within 3 working days. This will set off a Security Release Process.
30 -
31 -Any vulnerability information shared with Netdata Team stays within Netdata project and will not be disseminated to other projects unless it is necessary to get the issue fixed.
32 -
33 -As the security issue moves from triage, to identified fix, to release planning we will keep the reporter updated.
34 -
35 -## Public Disclosure Timing
36 -
37 -A public disclosure date is negotiated by the Netdata team and the bug submitter. We prefer to fully disclose the bug as soon as possible once a user mitigation is available. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested, or for vendor coordination. The timeframe for disclosure is from immediate (especially if it's already publicly known) to a few weeks. As a basic default, we expect report date to disclosure date to be on the order of 7 days. The Netdata team holds the final say when setting a disclosure date.
38 -
39 -[![analytics](https://www.google-analytics.com/collect?v=1&aip=1&t=pageview&_s=1&ds=github&dr=https%3A%2F%2Fgithub.com%2Fnetdata%2Fnetdata&dl=https%3A%2F%2Fmy-netdata.io%2Fgithub%2Fdocs%2FNetdata-Security-and-Disclosure-Information&_u=MAC~&cid=5792dfd7-8dc4-476b-af31-da2fdb9f93d2&tid=UA-64295674-3)]()
docs/generator/buildyaml.sh
+1 -1
@@ -127,6 +127,7 @@ echo -ne " - 'docs/Demo-Sites.md'
127 - REDISTRIBUTED.md
128 - CHANGELOG.md
129 - CONTRIBUTING.md
130 + - SECURITY.md
131 - Why Netdata:
132 - 'docs/why-netdata/README.md'
133 - 'docs/why-netdata/1s-granularity.md'
@@ -253,7 +254,6 @@ navpart 2 web/api/queries "" "Queries" 2
254
255 echo -ne "- Hacking Netdata:
256 - CODE_OF_CONDUCT.md
256 - - 'docs/Netdata-Security-and-Disclosure-Information.md'
257 - CONTRIBUTORS.md
258 "
259 navpart 2 packaging/makeself "" "" 4