Skip to content

Move vulnerability reporting to GitHub private vulnerability reporting - #11

Open
chrnorm wants to merge 3 commits into
mainfrom
github-vuln-reporting
Open

Move vulnerability reporting to GitHub private vulnerability reporting#11
chrnorm wants to merge 3 commits into
mainfrom
github-vuln-reporting

Conversation

@chrnorm

@chrnorm chrnorm commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

Proposed at the 2026-08-27 maintainers meeting: switch vulnerability reporting from the PGP-encrypted email process to GitHub private vulnerability reporting on the granted repository (already enabled).

  • The Vulnerability Reporting section now directs reporters to GitHub private vulnerability reporting, with granted-support@fwdcloudsec.org kept as a fallback for reporters without GitHub accounts
  • Adds a coordinated vulnerability disclosure subsection aligned with the EU Cyber Resilience Act: 5-business-day acknowledgement, remediation without undue delay, free security fixes via standard release channels, and public GitHub Security Advisories with CVEs once fixed
  • Retitles the PGP key section to "Release signing key" and clarifies it is used only for release verification, not vulnerability reports (anchors in the Release Verification section updated to match)

Companion PR on the granted repo: fwdcloudsec/granted#971

Replace the PGP-encrypted email reporting process with GitHub
private vulnerability reporting and add a coordinated disclosure
policy aligned with the EU Cyber Resilience Act. Retitle the PGP
section as the release signing key, since the key is no longer
used for vulnerability reports.
Comment thread src/content/docs/security.mdx Outdated
Comment on lines +91 to +97
We follow a coordinated vulnerability disclosure process, aligned with the requirements of the [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj):

- We aim to acknowledge your report within 5 business days.
- We will investigate, keep you informed of progress, and work with you on remediation.
- We will remediate confirmed vulnerabilities without undue delay and distribute security fixes free of charge through our standard release channels.
- Once a fix is available, we will publish a [GitHub Security Advisory](https://github.com/fwdcloudsec/granted/security/advisories) describing the vulnerability, its severity and impact, and the fixed versions, and request a CVE where appropriate.
- We ask that you do not publicly disclose the vulnerability until a fix has been released, and we will credit you in the advisory unless you prefer to remain anonymous.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure we need to specify this here wdyt

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Softened this to just the embargo ask — dropped the credit clause since it's already covered in the section intro. Applied the same change to SECURITY.md in fwdcloudsec/granted#971.

Credit for reporters is already covered in the section intro.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants