Skip to content

xcp-ng/xcp-ng-release

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

86 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Security policy

Reporting a vulnerability

If you discover a vulnerability in this project, please help us to manage it responsibly following these steps:

  1. Do not publicly disclose the vulnerability.

  2. You can email us at security@xcp-ng.org with the following details:

    • A clear description of the issue.
    • The steps to reproduce the vulnerability.
    • Any potential impact or possible attack scenarios.
  3. If you wish to report your vulnerability anonymously, you can contact the French Cybersecurity Agency (ANSSI). ANSSI must protect the confidentiality of the identity of the researcher who reports the vulnerability, in line with CVD policies in the EU.

Reporters can expect a quick response, acknowledging the issue was received.

Disclosure

If the vulnerability is accepted, we will work with the reporter to establish a remediation timeline.

Coordinated disclosure timeline

  • We aim to release a patch or mitigation within 90 days of triage acceptance.
  • The public disclosure date is negotiated jointly by the security team and the reporter, and is typically set to coincide with the release of a patch or user-facing mitigation.
  • If no agreement is reached within 30 days, either party may request arbitration from a recognized national CERT (e.g. CERT-FR) or CERT/CC. Both parties agree to accept the disclosure timeline recommended by the arbitrating CERT.

What to expect

  • Reporters are kept informed of triage status and remediation progress.
  • Credit is given to the reporter in the VSA unless anonymity is requested.

If a reported issue is declined (e.g. out of scope, not reproducible, or a known risk), we will explain the reasoning to the reporter.

Thank you for your help in keeping this project secure !

About

Various configuration files for XCP-ng

Security policy

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages