Skip to content

Security: canonical/repo-policy-compliance

SECURITY.md

Security policy

What qualifies as a security issue

Credentials leakage, outdated dependencies with known vulnerabilities, and other issues that could lead to unprivileged or unauthorised access to the database or the system.

Reporting a vulnerability

The easiest way to report a security issue is through GitHub. See Privately reporting a security vulnerability for instructions.

The repository admins will be notified of the issue and will work with you to determine whether the issue qualifies as a security issue and, if so, in which component. We will then handle figuring out a fix, getting a CVE assigned and coordinating the release of the fix.

The Ubuntu Security disclosure and embargo policy contains more information about what you can expect when you contact us, and what we expect from you.

There aren’t any published security advisories