agama/SECURITY.md
José Iván López González e3f3257ded Add security documentation
2023-04-05 16:30:28 +01:00

30 lines
1.2 KiB
Markdown

# Security Bugs
Security related bugs need a special handling because we need to make sure that the fix is available
for all affected users at the time of publishing the security vulnerability.
Thank you for your cooperation! :+1:
## Reporting Security Bugs
For reporting security related issues use the *Security* component in the SUSE
Bugzilla, just follow [this link](
https://bugzilla.suse.com/enter_bug.cgi?format=guided&product=alp&component=Security).
:warning: *Please DO NOT use any publicly visible places like mailing lists
or GitHub issues for reporting or discussing any security related issues!*
The security bugs in Bugzilla are only visible for the reporter and the security
team. When the security team confirms the issue they will make it visible for
the Agama developers.
## Sending or Proposing Security Fixes
A similar rule applies to sending or proposing security related fixes: report a
[security bug](
https://bugzilla.suse.com/enter_bug.cgi?format=guided&product=alp&component=Security)
in Bugzilla and attach the proposed patch there.
:warning: *Please DO NOT open pull requests with security fixes at GitHub!
You should also avoid committing the fix to your fork or anywhere where it
can be seen by public.*