This repository follows the ResQ organisation's security policy, which covers scope, response times and disclosure. This file restates how to report a vulnerability in this repository and adds the sections below.
As the organisation policy's supported-versions table sets out, security fixes go to the latest published version only. If you run an older one, please check whether the issue still affects the latest version, as it may already be fixed. Reports about older versions are still welcome; say which commit or release tag you tested.
Do not open a public issue for a suspected vulnerability. Use one of these private channels:
- GitHub private vulnerability reporting (preferred): open a draft advisory on this repository.
- Email:
security@resq.software.
Please include the affected commit SHA or release tag, a short description of the issue and its impact, and steps to reproduce.
Where the EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to a product in this repository, ResQ reports through ENISA's Single Reporting Platform, to the CSIRT designated as coordinator and to ENISA:
- Actively exploited vulnerabilities: an early warning within 24 hours of becoming aware of one, a notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available.
- Severe incidents affecting the security of the product: an early warning within 24 hours, a notification within 72 hours, and a final report within one month of the notification.
We inform affected users as the Act requires. Reporting to us through the private channels above never requires you to contact ENISA yourself. You may also report to a national CSIRT under its coordinated vulnerability disclosure policy.
If you make a good-faith effort to follow this policy while researching a vulnerability, we will:
- treat your research as authorised, and not pursue or support legal action against you for it;
- work with you to understand and fix the issue quickly; and
- credit you, unless you ask us not to.
Good faith means that you:
- test only against your own accounts, data and installations;
- stop and report as soon as you find a vulnerability;
- access, change or keep no one else's data beyond what's needed to show the issue;
- don't degrade our services or anyone else's; and
- give us reasonable time to fix the issue before you disclose it.
This safe harbour covers ResQ's own claims only; it cannot bind third parties.