Skip to content

Security: fluiderson/cf

SECURITY.md

Security Policy

Reporting Vulnerabilities

Do NOT report security vulnerabilities through public GitHub issues.

Report vulnerabilities via:

  1. GitHub Security Advisories: Report privately at cyberfabric/cyberfabric-core/security/advisories/new
  2. Direct Contact: Email security team (security@acronis.com) and maintainers directly

Required Information

  • Vulnerability type
  • Affected source file paths
  • Source location (tag/branch/commit or URL)
  • Reproduction steps
  • Configuration requirements (if any)
  • Proof-of-concept code (if available)
  • Impact assessment

Response Timeline

  • Acknowledgment: 48 hours
  • Fix target: 7-90 days from disclosure, depending on severity
  • Credit: Provided in security advisory (unless anonymity requested)

Developer Security Practices

Disclosure Process

  1. Security advisory published
  2. Patch release created
  3. Notification via GitHub releases
  4. Public disclosure after update window

There aren’t any published security advisories