We take security very seriously at SDA SE. We welcome any review of the latest release of all our open source code to ensure that these components can not be compromised. In case you identified a security related issue with severity of low to medium, please create a GitHub issue.
In case you identified a security related issue with severity of high or critical, please disclose information about the issue non public via email to opensource-security@sda.se
.
We encourage researchers to include a Proof-of-Concept, supported by screenshots or videos. For each given security related issue with severity high or critical (based on SDA SE own assessment), we will respond within one week.
Please be aware that only the most recent version will be subject of security patches. The changelog provides information about feature and security related fixes like patches.
This project uses Semantic Versioning. Images are build nightly and receive automatic update for the operating system components. Images are immutable in this project, so the patch version is increased each night.
There is no format in commits to identify security related fixes and it is not planned yet.