Thank you for helping make everyone safe. If you found a security concern with our project(s) then we certainly want to hear about it.
If you found a security issue then please send it to mailto:security@vega-strike.org The mailing list includes the core team responsible for addressing any security issues.
Please also be patient with us as while we do take security seriously we also are a team of volunteers and not everyone may check their email timeline.
If there is an emergency situation then please do the following:
- Send the email per our contact information above.
- Please reach out to us in gitter.im to alert us that there is something we need to look for. Do not tell us what the issue is there.
Before releasing something publicly we need a moment to review and potentially address it. We ask that you give us the normal amount of time that most organizations get to address concerns before releasing anything publicly - 30/60/90 days. If we do not respond within that timeframe than you are certainly free to disclose.
Our goal is to have the conversation with you before ringing the alarm bells. Too many alarm bells and people will not take the threats seriously. So let's work together - if we do, then we'll raise the red flag where appropriate to alert our entire community.
We ask that you give us an industry-standard response time.
Infrastructure is not code or deliverables themselves though that there might be downstream effects.
Infrastructure consists of:
- email servers
- websites
- forums
- communication channels (gitter.im, matrix.io, IRC, etc)
- compromised accounts (our Github Organizations, social media accounts, etc) - anything you see that bears our name and that we claim ownership to.
Deliverables consists of the files we publish in the releases on Github and other places that we own and maintain.
Once confirmed the deliverables will be removed and if necessary regenerated if we can. If our older releases are compromised we might not be able to regenerate them beyond the source code deliverable.
If there is someone else that is mirroring our deliverables and those mirros have been compromised then please contact them. Feel free to let us know about it as well so we can appropriately alert our community; however, there will be little we can do about it beyond that.
If there is a security bug in the code, then please let us know via our contact information above.
Once you have initiated contact that you can help speed up the process by the following:
- Please submit a PR
- Be discreet about what is being fixed and why. Do not raise the alarm bells in the PR; but do note that you alerted us via our security contact policy.
- Please provide enough information that we can evaluate what is being fixed and why. However remember that this is in the public form.
We cannot guarantee a new release will happen within 30 days as it will certainly depend on a number of factors such as:
- where it is
- whether it is in an existing release
- if it is in a supported release
However we will do what we can to keep people safe and alert the community as appropriate.
We ask that you give us 30 days to start the discussion. As part of the discussion we will discuss what longer time frames may be required.