From 49f8f055189745950b72483871be9c80dd8e4ae6 Mon Sep 17 00:00:00 2001 From: Steven Kirk Date: Fri, 31 Jul 2026 16:44:14 +0200 Subject: [PATCH] Expand security policy with response expectations and scope (#21901) * Expand security policy with response expectations, supported versions and scope Part of the coordinated vulnerability disclosure rollout: document response-time commitments (acknowledge in 2 business days, timeline in 10), state the supported-versions policy (12.x), and clarify which packages this policy covers. Co-authored-by: Claude Fable 5 Co-authored-by: Mike James --- SECURITY.md | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/SECURITY.md b/SECURITY.md index 7b30c0cdf8..2c1637fd04 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,4 +1,5 @@ # Security Policy +Avalonia is free and open-source software published by AvaloniaUI OÜ. The framework is made publicly available at no charge and is not placed on the market within the meaning of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). AvaloniaUI OÜ acts as the project's open-source software steward and maintains this cybersecurity policy in that capacity, in line with Article 24 of that Regulation. ## Reporting a Vulnerability @@ -21,5 +22,25 @@ https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/ ### Reporting via Email Alternatively, you may report security vulnerabilities by emailing security@avaloniaui.net. -### Misc +### What to Expect + +- We aim to acknowledge your report within **2 business days**. +- We aim to confirm whether we consider it a vulnerability and to share a remediation timeline within **10 business days**. +- We will keep you informed of progress and coordinate the disclosure date with you. +- We will credit you in the published advisory unless you ask us not to. + +These timescales are the targets we work to for the open-source project; they are not contractual commitments. Organisations that require contractually binding response and remediation times can obtain them under a commercial agreement. + Please note that Avalonia does not operate a bug bounty programme. + +## Versions Receiving Security Fixes +| Version | Security fixes | +|---|---| +| 11.x and older | Not provided | +| 12.x (current stable) | Provided | + +Security fixes are delivered at the head of the current stable series. If a vulnerability affects earlier 12.x releases, we fix it in a new release of the latest version, and the remediation path is to upgrade to that release. Security fixes for the current series are published openly and free of charge. Access to Avalonia's open-source releases, updates and security fixes is never conditional on payment. + +## Scope + +This policy covers the Avalonia framework packages published from this repository (`Avalonia` and the `Avalonia.*` platform and integration packages).