diff --git a/SECURITY.md b/SECURITY.md index fcaa7282..1f4be01e 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,3 +1,45 @@ -# Security Disclosures +# Security Policy -Please see [our community docs](https://oauth2-proxy.github.io/oauth2-proxy/community/security) for our security policy. +## Reporting a Vulnerability + +If you believe you have found a vulnerability in OAuth2 Proxy or one of its +dependencies, do not open a public GitHub issue or pull request, and do not +share details publicly. Please report it privately by emailing +[security@oauth2-proxy.dev](mailto:security@oauth2-proxy.dev). + +OAuth2 Proxy is maintained by volunteers. We will investigate reports and +respond on a best-effort basis; this may take longer than projects with +dedicated, full-time security teams. + +## What to Report + +Please report vulnerabilities that have a demonstrable security impact in a +supported OAuth2 Proxy configuration. Insecure default configuration options +are not, by themselves, security vulnerabilities. + +Do not report dependency CVEs solely because they appear in vulnerability scan +output. We monitor dependency scans, including GitHub's alerts, ourselves. +Reports of dependency vulnerabilities should explain how OAuth2 Proxy is +affected and include a reproducible exploit or other evidence of impact. + +Please include as much detail as possible, ideally: + +- A reproducible case that demonstrates the vulnerability +- How you discovered the vulnerability +- A potential fix, if you have one +- Affected versions, if the issue is not present in the main branch +- Your GitHub username + +## Disclosure Process + +We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories) +to discuss fixes privately. If you include your GitHub username, we can add you +as a collaborator so that you can participate in the discussion and validate +proposed fixes. + +For minor issues and already-disclosed vulnerabilities, typically in +dependencies, we may use a regular pull request instead of a security advisory. + +After agreeing on a fix, we will merge it and make a release. When several +security issues are in progress, we may wait until all patches are ready. +Backports to previous releases are at the maintainers' discretion. diff --git a/docs/docs/community/security.md b/docs/docs/community/security.md index 00cdb724..eb463737 100644 --- a/docs/docs/community/security.md +++ b/docs/docs/community/security.md @@ -3,47 +3,7 @@ id: security title: Security --- -:::note -OAuth2 Proxy is a community project. -Maintainers do not work on this project full time, and as such, -while we endeavour to respond to disclosures as quickly as possible, -this may take longer than in projects with corporate sponsorship. -::: - ## Security Disclosures -:::important -If you believe you have found a vulnerability within OAuth2 Proxy or any of its -dependencies, please do NOT open an issue or PR on GitHub, please do NOT post -any details publicly. -::: - -Security disclosures MUST be done in private. -If you have found an issue that you would like to bring to the attention of the -maintenance team for OAuth2 Proxy, please compose an email and send it to the -list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file. - -Please include as much detail as possible. -Ideally, your disclosure should include: -- A reproducible case that can be used to demonstrate the exploit -- How you discovered this vulnerability -- A potential fix for the issue (if you have thought of one) -- Versions affected (if not present in master) -- Your GitHub ID - -### How will we respond to disclosures? - -We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories) -to privately discuss fixes for disclosed vulnerabilities. -If you include a GitHub ID with your disclosure we will add you as a collaborator -for the advisory so that you can join the discussion and validate any fixes -we may propose. - -For minor issues and previously disclosed vulnerabilities (typically for -dependencies), we may use regular PRs for fixes and forego the security advisory. - -Once a fix has been agreed upon, we will merge the fix and create a new release. -If we have multiple security issues in flight simultaneously, we may delay -merging fixes until all patches are ready. -We may also backport the fix to previous releases, -but this will be at the discretion of the maintainers. +The canonical security policy, including how to report a vulnerability, is in +the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md). diff --git a/docs/versioned_docs/version-7.15.x/community/security.md b/docs/versioned_docs/version-7.15.x/community/security.md index 00cdb724..eb463737 100644 --- a/docs/versioned_docs/version-7.15.x/community/security.md +++ b/docs/versioned_docs/version-7.15.x/community/security.md @@ -3,47 +3,7 @@ id: security title: Security --- -:::note -OAuth2 Proxy is a community project. -Maintainers do not work on this project full time, and as such, -while we endeavour to respond to disclosures as quickly as possible, -this may take longer than in projects with corporate sponsorship. -::: - ## Security Disclosures -:::important -If you believe you have found a vulnerability within OAuth2 Proxy or any of its -dependencies, please do NOT open an issue or PR on GitHub, please do NOT post -any details publicly. -::: - -Security disclosures MUST be done in private. -If you have found an issue that you would like to bring to the attention of the -maintenance team for OAuth2 Proxy, please compose an email and send it to the -list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file. - -Please include as much detail as possible. -Ideally, your disclosure should include: -- A reproducible case that can be used to demonstrate the exploit -- How you discovered this vulnerability -- A potential fix for the issue (if you have thought of one) -- Versions affected (if not present in master) -- Your GitHub ID - -### How will we respond to disclosures? - -We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories) -to privately discuss fixes for disclosed vulnerabilities. -If you include a GitHub ID with your disclosure we will add you as a collaborator -for the advisory so that you can join the discussion and validate any fixes -we may propose. - -For minor issues and previously disclosed vulnerabilities (typically for -dependencies), we may use regular PRs for fixes and forego the security advisory. - -Once a fix has been agreed upon, we will merge the fix and create a new release. -If we have multiple security issues in flight simultaneously, we may delay -merging fixes until all patches are ready. -We may also backport the fix to previous releases, -but this will be at the discretion of the maintainers. +The canonical security policy, including how to report a vulnerability, is in +the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md).