Skip to content

Latest commit

 

History

History
27 lines (19 loc) · 1.07 KB

SECURITY.md

File metadata and controls

27 lines (19 loc) · 1.07 KB

Security Policy

Supported Versions

We provide security updates for develop and for the last two stable (0.x) release series of Spack. Security updates will be made available as patch (0.x.1, 0.x.2, etc.) releases.

For more on Spack's release structure, see README.md.

Reporting a Vulnerability

You can report a vulnerability using GitHub's private reporting feature:

  1. Go to github.com/spack/spack/security.
  2. Click "Report a vulnerability" in the upper right corner of that page.
  3. Fill out the form and submit your draft security advisory.

More details are available in GitHub's docs.

You can expect to hear back about security issues within two days. If your security issue is accepted, we will do our best to release a fix within a week. If fixing the issue will take longer than this, we will discuss timeline options with you.