Skip to content

Commit

Permalink
📝 SECURITY: Add disclosure policy
Browse files Browse the repository at this point in the history
  • Loading branch information
Pierre Goiffon committed Dec 20, 2022
1 parent 9081afb commit 0ad4af6
Showing 1 changed file with 9 additions and 2 deletions.
11 changes: 9 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,7 @@ to [itop-security@combodo.com](mailto:itop-security@combodo.com).



## 📆 Disclosure Policy

## 🔍 Combodo acknowledgment and investigation
Report sent to us will be acknowledged within the week.

Then, a Combodo developer will be assigned to the reported issue and will:
Expand All @@ -34,3 +33,11 @@ Then, a Combodo developer will be assigned to the reported issue and will:
Security issues always take precedence over bug fixes and feature work.

The assignee will keep you informed of the resolution progress, and may ask you for additional information or guidance.


## 📆 Disclosure Policy
Once the fix is done and acknowledged by every stakeholder, it will be included in the next module version.

The release communications will include the information of the vulnerability fix.

Corresponding GitHub advisories and CVE will be published 3 months after the extension version release date so that iTop instances can be updated.

0 comments on commit 0ad4af6

Please sign in to comment.