docs: update and consolidate security disclosure process notice (#3537)

Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
Jan Larwig
2026-09-13 15:22:39 +02:00
committed by GitHub
parent 33c2eb92de
commit 6420aae790
3 changed files with 48 additions and 86 deletions
+44 -2
View File
@@ -1,3 +1,45 @@
# Security Disclosures
# Security Policy
Please see [our community docs](https://oauth2-proxy.github.io/oauth2-proxy/community/security) for our security policy.
## Reporting a Vulnerability
If you believe you have found a vulnerability in OAuth2 Proxy or one of its
dependencies, do not open a public GitHub issue or pull request, and do not
share details publicly. Please report it privately by emailing
[security@oauth2-proxy.dev](mailto:security@oauth2-proxy.dev).
OAuth2 Proxy is maintained by volunteers. We will investigate reports and
respond on a best-effort basis; this may take longer than projects with
dedicated, full-time security teams.
## What to Report
Please report vulnerabilities that have a demonstrable security impact in a
supported OAuth2 Proxy configuration. Insecure default configuration options
are not, by themselves, security vulnerabilities.
Do not report dependency CVEs solely because they appear in vulnerability scan
output. We monitor dependency scans, including GitHub's alerts, ourselves.
Reports of dependency vulnerabilities should explain how OAuth2 Proxy is
affected and include a reproducible exploit or other evidence of impact.
Please include as much detail as possible, ideally:
- A reproducible case that demonstrates the vulnerability
- How you discovered the vulnerability
- A potential fix, if you have one
- Affected versions, if the issue is not present in the main branch
- Your GitHub username
## Disclosure Process
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
to discuss fixes privately. If you include your GitHub username, we can add you
as a collaborator so that you can participate in the discussion and validate
proposed fixes.
For minor issues and already-disclosed vulnerabilities, typically in
dependencies, we may use a regular pull request instead of a security advisory.
After agreeing on a fix, we will merge it and make a release. When several
security issues are in progress, we may wait until all patches are ready.
Backports to previous releases are at the maintainers' discretion.
+2 -42
View File
@@ -3,47 +3,7 @@ id: security
title: Security
---
:::note
OAuth2 Proxy is a community project.
Maintainers do not work on this project full time, and as such,
while we endeavour to respond to disclosures as quickly as possible,
this may take longer than in projects with corporate sponsorship.
:::
## Security Disclosures
:::important
If you believe you have found a vulnerability within OAuth2 Proxy or any of its
dependencies, please do NOT open an issue or PR on GitHub, please do NOT post
any details publicly.
:::
Security disclosures MUST be done in private.
If you have found an issue that you would like to bring to the attention of the
maintenance team for OAuth2 Proxy, please compose an email and send it to the
list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file.
Please include as much detail as possible.
Ideally, your disclosure should include:
- A reproducible case that can be used to demonstrate the exploit
- How you discovered this vulnerability
- A potential fix for the issue (if you have thought of one)
- Versions affected (if not present in master)
- Your GitHub ID
### How will we respond to disclosures?
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
to privately discuss fixes for disclosed vulnerabilities.
If you include a GitHub ID with your disclosure we will add you as a collaborator
for the advisory so that you can join the discussion and validate any fixes
we may propose.
For minor issues and previously disclosed vulnerabilities (typically for
dependencies), we may use regular PRs for fixes and forego the security advisory.
Once a fix has been agreed upon, we will merge the fix and create a new release.
If we have multiple security issues in flight simultaneously, we may delay
merging fixes until all patches are ready.
We may also backport the fix to previous releases,
but this will be at the discretion of the maintainers.
The canonical security policy, including how to report a vulnerability, is in
the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md).
@@ -3,47 +3,7 @@ id: security
title: Security
---
:::note
OAuth2 Proxy is a community project.
Maintainers do not work on this project full time, and as such,
while we endeavour to respond to disclosures as quickly as possible,
this may take longer than in projects with corporate sponsorship.
:::
## Security Disclosures
:::important
If you believe you have found a vulnerability within OAuth2 Proxy or any of its
dependencies, please do NOT open an issue or PR on GitHub, please do NOT post
any details publicly.
:::
Security disclosures MUST be done in private.
If you have found an issue that you would like to bring to the attention of the
maintenance team for OAuth2 Proxy, please compose an email and send it to the
list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file.
Please include as much detail as possible.
Ideally, your disclosure should include:
- A reproducible case that can be used to demonstrate the exploit
- How you discovered this vulnerability
- A potential fix for the issue (if you have thought of one)
- Versions affected (if not present in master)
- Your GitHub ID
### How will we respond to disclosures?
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
to privately discuss fixes for disclosed vulnerabilities.
If you include a GitHub ID with your disclosure we will add you as a collaborator
for the advisory so that you can join the discussion and validate any fixes
we may propose.
For minor issues and previously disclosed vulnerabilities (typically for
dependencies), we may use regular PRs for fixes and forego the security advisory.
Once a fix has been agreed upon, we will merge the fix and create a new release.
If we have multiple security issues in flight simultaneously, we may delay
merging fixes until all patches are ready.
We may also backport the fix to previous releases,
but this will be at the discretion of the maintainers.
The canonical security policy, including how to report a vulnerability, is in
the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md).