xref: /freebsd/sys/contrib/openzfs/SECURITY.md (revision 22649d4dba730d46244fd2dff4fd174903c8379f)
1*22649d4dSMartin Matuska# Security Policy
2*22649d4dSMartin Matuska
3*22649d4dSMartin Matuska## Reporting a Vulnerability
4*22649d4dSMartin Matuska
5*22649d4dSMartin MatuskaWe encourage responsible disclosure of security vulnerabilities. If you
6*22649d4dSMartin Matuskafind something suspicious, we encourage and appreciate your report.
7*22649d4dSMartin Matuska
8*22649d4dSMartin MatuskaThe preferred way to report a vulnerability is to use the
9*22649d4dSMartin Matuska**"Report a vulnerability"** button under the **Security** tab of the
10*22649d4dSMartin MatuskaOpenZFS GitHub repository. This creates a private communication channel
11*22649d4dSMartin Matuskabetween you and the maintainers, allowing us to review the report
12*22649d4dSMartin Matuskaconfidentially and respond as quickly as possible.
13*22649d4dSMartin Matuska
14*22649d4dSMartin MatuskaPlease include, if possible:
15*22649d4dSMartin Matuska
16*22649d4dSMartin Matuska- A clear description of the issue
17*22649d4dSMartin Matuska- Steps to reproduce the problem
18*22649d4dSMartin Matuska- Affected versions or branches
19*22649d4dSMartin Matuska- Any proof of concept, logs, or screenshots
20*22649d4dSMartin Matuska- Your assessment of the potential impact
21*22649d4dSMartin Matuska
22*22649d4dSMartin Matuska## What to Expect
23*22649d4dSMartin Matuska
24*22649d4dSMartin Matuska- We will review security reports as soon as practical.
25*22649d4dSMartin Matuska- We may ask follow-up questions to better understand the issue.
26*22649d4dSMartin Matuska- Please allow time for investigation and coordination before public
27*22649d4dSMartin Matuska  disclosure.
28*22649d4dSMartin Matuska- If the issue is confirmed, we will work on a fix and release a security
29*22649d4dSMartin Matuska  update as needed for supported OpenZFS versions.
30