Browse Source

Maintenance: Add a short security process overview.

Martin Gruner 8 months ago
parent
commit
05f6aa2eef
1 changed files with 8 additions and 0 deletions
  1. 8 0
      SECURITY.md

+ 8 - 0
SECURITY.md

@@ -43,3 +43,11 @@ in the related security advisory.
 
 Zammad does not offer financial compensation through a
 security bounty program.
+
+## Process Overview
+
+- Potential security issues can be reported via security@zammad.com.
+- We evaluate them and provide timely feedback to the reporter.
+- There may be security releases created if needed, e.g. https://zammad.com/en/releases/6-3-1.
+- We publish security advisories for every acknowledged issue, like https://zammad.com/en/advisories/zaa-2024-04.
+- After their publication, we request CVE identifiers to be assigned to the advisories.