mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-09-30 03:31:27 +02:00
docs: update and consolidate security disclosure process notice (#3537)
Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
+44
-2
@@ -1,3 +1,45 @@
|
|||||||
# Security Disclosures
|
# Security Policy
|
||||||
|
|
||||||
Please see [our community docs](https://oauth2-proxy.github.io/oauth2-proxy/community/security) for our security policy.
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
|
If you believe you have found a vulnerability in OAuth2 Proxy or one of its
|
||||||
|
dependencies, do not open a public GitHub issue or pull request, and do not
|
||||||
|
share details publicly. Please report it privately by emailing
|
||||||
|
[security@oauth2-proxy.dev](mailto:security@oauth2-proxy.dev).
|
||||||
|
|
||||||
|
OAuth2 Proxy is maintained by volunteers. We will investigate reports and
|
||||||
|
respond on a best-effort basis; this may take longer than projects with
|
||||||
|
dedicated, full-time security teams.
|
||||||
|
|
||||||
|
## What to Report
|
||||||
|
|
||||||
|
Please report vulnerabilities that have a demonstrable security impact in a
|
||||||
|
supported OAuth2 Proxy configuration. Insecure default configuration options
|
||||||
|
are not, by themselves, security vulnerabilities.
|
||||||
|
|
||||||
|
Do not report dependency CVEs solely because they appear in vulnerability scan
|
||||||
|
output. We monitor dependency scans, including GitHub's alerts, ourselves.
|
||||||
|
Reports of dependency vulnerabilities should explain how OAuth2 Proxy is
|
||||||
|
affected and include a reproducible exploit or other evidence of impact.
|
||||||
|
|
||||||
|
Please include as much detail as possible, ideally:
|
||||||
|
|
||||||
|
- A reproducible case that demonstrates the vulnerability
|
||||||
|
- How you discovered the vulnerability
|
||||||
|
- A potential fix, if you have one
|
||||||
|
- Affected versions, if the issue is not present in the main branch
|
||||||
|
- Your GitHub username
|
||||||
|
|
||||||
|
## Disclosure Process
|
||||||
|
|
||||||
|
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
|
||||||
|
to discuss fixes privately. If you include your GitHub username, we can add you
|
||||||
|
as a collaborator so that you can participate in the discussion and validate
|
||||||
|
proposed fixes.
|
||||||
|
|
||||||
|
For minor issues and already-disclosed vulnerabilities, typically in
|
||||||
|
dependencies, we may use a regular pull request instead of a security advisory.
|
||||||
|
|
||||||
|
After agreeing on a fix, we will merge it and make a release. When several
|
||||||
|
security issues are in progress, we may wait until all patches are ready.
|
||||||
|
Backports to previous releases are at the maintainers' discretion.
|
||||||
|
|||||||
@@ -3,47 +3,7 @@ id: security
|
|||||||
title: Security
|
title: Security
|
||||||
---
|
---
|
||||||
|
|
||||||
:::note
|
|
||||||
OAuth2 Proxy is a community project.
|
|
||||||
Maintainers do not work on this project full time, and as such,
|
|
||||||
while we endeavour to respond to disclosures as quickly as possible,
|
|
||||||
this may take longer than in projects with corporate sponsorship.
|
|
||||||
:::
|
|
||||||
|
|
||||||
## Security Disclosures
|
## Security Disclosures
|
||||||
|
|
||||||
:::important
|
The canonical security policy, including how to report a vulnerability, is in
|
||||||
If you believe you have found a vulnerability within OAuth2 Proxy or any of its
|
the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md).
|
||||||
dependencies, please do NOT open an issue or PR on GitHub, please do NOT post
|
|
||||||
any details publicly.
|
|
||||||
:::
|
|
||||||
|
|
||||||
Security disclosures MUST be done in private.
|
|
||||||
If you have found an issue that you would like to bring to the attention of the
|
|
||||||
maintenance team for OAuth2 Proxy, please compose an email and send it to the
|
|
||||||
list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file.
|
|
||||||
|
|
||||||
Please include as much detail as possible.
|
|
||||||
Ideally, your disclosure should include:
|
|
||||||
- A reproducible case that can be used to demonstrate the exploit
|
|
||||||
- How you discovered this vulnerability
|
|
||||||
- A potential fix for the issue (if you have thought of one)
|
|
||||||
- Versions affected (if not present in master)
|
|
||||||
- Your GitHub ID
|
|
||||||
|
|
||||||
### How will we respond to disclosures?
|
|
||||||
|
|
||||||
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
|
|
||||||
to privately discuss fixes for disclosed vulnerabilities.
|
|
||||||
If you include a GitHub ID with your disclosure we will add you as a collaborator
|
|
||||||
for the advisory so that you can join the discussion and validate any fixes
|
|
||||||
we may propose.
|
|
||||||
|
|
||||||
For minor issues and previously disclosed vulnerabilities (typically for
|
|
||||||
dependencies), we may use regular PRs for fixes and forego the security advisory.
|
|
||||||
|
|
||||||
Once a fix has been agreed upon, we will merge the fix and create a new release.
|
|
||||||
If we have multiple security issues in flight simultaneously, we may delay
|
|
||||||
merging fixes until all patches are ready.
|
|
||||||
We may also backport the fix to previous releases,
|
|
||||||
but this will be at the discretion of the maintainers.
|
|
||||||
|
|||||||
@@ -3,47 +3,7 @@ id: security
|
|||||||
title: Security
|
title: Security
|
||||||
---
|
---
|
||||||
|
|
||||||
:::note
|
|
||||||
OAuth2 Proxy is a community project.
|
|
||||||
Maintainers do not work on this project full time, and as such,
|
|
||||||
while we endeavour to respond to disclosures as quickly as possible,
|
|
||||||
this may take longer than in projects with corporate sponsorship.
|
|
||||||
:::
|
|
||||||
|
|
||||||
## Security Disclosures
|
## Security Disclosures
|
||||||
|
|
||||||
:::important
|
The canonical security policy, including how to report a vulnerability, is in
|
||||||
If you believe you have found a vulnerability within OAuth2 Proxy or any of its
|
the repository's [SECURITY.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/SECURITY.md).
|
||||||
dependencies, please do NOT open an issue or PR on GitHub, please do NOT post
|
|
||||||
any details publicly.
|
|
||||||
:::
|
|
||||||
|
|
||||||
Security disclosures MUST be done in private.
|
|
||||||
If you have found an issue that you would like to bring to the attention of the
|
|
||||||
maintenance team for OAuth2 Proxy, please compose an email and send it to the
|
|
||||||
list of maintainers in our [MAINTAINERS.md](https://github.com/oauth2-proxy/oauth2-proxy/blob/master/MAINTAINERS.md) file.
|
|
||||||
|
|
||||||
Please include as much detail as possible.
|
|
||||||
Ideally, your disclosure should include:
|
|
||||||
- A reproducible case that can be used to demonstrate the exploit
|
|
||||||
- How you discovered this vulnerability
|
|
||||||
- A potential fix for the issue (if you have thought of one)
|
|
||||||
- Versions affected (if not present in master)
|
|
||||||
- Your GitHub ID
|
|
||||||
|
|
||||||
### How will we respond to disclosures?
|
|
||||||
|
|
||||||
We use [GitHub Security Advisories](https://docs.github.com/en/github/managing-security-vulnerabilities/about-github-security-advisories)
|
|
||||||
to privately discuss fixes for disclosed vulnerabilities.
|
|
||||||
If you include a GitHub ID with your disclosure we will add you as a collaborator
|
|
||||||
for the advisory so that you can join the discussion and validate any fixes
|
|
||||||
we may propose.
|
|
||||||
|
|
||||||
For minor issues and previously disclosed vulnerabilities (typically for
|
|
||||||
dependencies), we may use regular PRs for fixes and forego the security advisory.
|
|
||||||
|
|
||||||
Once a fix has been agreed upon, we will merge the fix and create a new release.
|
|
||||||
If we have multiple security issues in flight simultaneously, we may delay
|
|
||||||
merging fixes until all patches are ready.
|
|
||||||
We may also backport the fix to previous releases,
|
|
||||||
but this will be at the discretion of the maintainers.
|
|
||||||
|
|||||||
Reference in New Issue
Block a user