You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Open-CMSIS-Pack vscode-cmsis-debugger maintainers take security issues seriously and appreciate responsible disclosure. Your efforts to improve project security are highly valued.
14
+
15
+
We use GitHub's [private vulnerability reporting](https://docs.github.com/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) guidelines.
16
+
To report a security issue, please click on [Report a vulnerability](https://github.com/Open-CMSIS-Pack/vscode-cmsis-debugger/security/advisories/new) and include:
17
+
18
+
- A detailed description of the issue
19
+
- Steps to reproduce the vulnerability
20
+
- Affected project versions
21
+
- Any known mitigations
22
+
23
+
A maintainer will acknowledge your report as soon as possible and guide the next steps. We will keep you informed of progress toward a fix and may request additional details if needed.
24
+
25
+
## Vulnerability Management
26
+
27
+
Once a security issue is reported, the maintainers will:
28
+
29
+
1. Confirm the issue
30
+
2. Identify/Confirm affected versions
31
+
3. Audit related code for similar vulnerabilities
32
+
4. Develop and release patches for maintained versions
33
+
34
+
## Improving This Policy
35
+
36
+
If you have suggestions for improving this process, please open an issue or submit a pull request.
0 commit comments