Browse Source

Expand security policy with response expectations and scope (#21901)

* Expand security policy with response expectations, supported versions and scope

Part of the coordinated vulnerability disclosure rollout: document
response-time commitments (acknowledge in 2 business days, timeline in
10), state the supported-versions policy (12.x), and clarify which
packages this policy covers.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Mike James <mike@avaloniaui.net>
package-control-catalog
Steven Kirk 2 months ago
committed by GitHub
parent
commit
49f8f05518
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 23
      SECURITY.md

23
SECURITY.md

@ -1,4 +1,5 @@
# Security Policy
Avalonia is free and open-source software published by AvaloniaUI OÜ. The framework is made publicly available at no charge and is not placed on the market within the meaning of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). AvaloniaUI OÜ acts as the project's open-source software steward and maintains this cybersecurity policy in that capacity, in line with Article 24 of that Regulation.
## Reporting a Vulnerability
@ -21,5 +22,25 @@ https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/
### Reporting via Email
Alternatively, you may report security vulnerabilities by emailing security@avaloniaui.net.
### Misc
### What to Expect
- We aim to acknowledge your report within **2 business days**.
- We aim to confirm whether we consider it a vulnerability and to share a remediation timeline within **10 business days**.
- We will keep you informed of progress and coordinate the disclosure date with you.
- We will credit you in the published advisory unless you ask us not to.
These timescales are the targets we work to for the open-source project; they are not contractual commitments. Organisations that require contractually binding response and remediation times can obtain them under a commercial agreement.
Please note that Avalonia does not operate a bug bounty programme.
## Versions Receiving Security Fixes
| Version | Security fixes |
|---|---|
| 11.x and older | Not provided |
| 12.x (current stable) | Provided |
Security fixes are delivered at the head of the current stable series. If a vulnerability affects earlier 12.x releases, we fix it in a new release of the latest version, and the remediation path is to upgrade to that release. Security fixes for the current series are published openly and free of charge. Access to Avalonia's open-source releases, updates and security fixes is never conditional on payment.
## Scope
This policy covers the Avalonia framework packages published from this repository (`Avalonia` and the `Avalonia.*` platform and integration packages).

Loading…
Cancel
Save