ADVISORIES

Security Advisories

A publication framework for affected versions, severity, mitigation, fixed releases and coordinated disclosure.

STATE

Current public state.

STATE

Current public state.

  • No advisory data is included in this website package
  • Production deployment must connect this page to the approved advisory register
  • Absence of a public advisory is not a statement that no vulnerability exists

FIELDS

Required advisory fields.

FIELDS

Required advisory fields.

  • Advisory ID and publication date
  • Affected product, version and configuration
  • Severity and technical impact
  • Mitigation or workaround
  • Fixed version and upgrade path
  • CVE/CWE reference where assigned

DISCLOSE

Coordinated disclosure.

DISCLOSE

Coordinated disclosure.

  • Use security.txt for the approved contact
  • Acknowledge receipt and protect reporter data
  • Triage, reproduce and scope the issue
  • Coordinate remediation and publication
  • Preserve evidence and lessons learned