1*22649d4dSMartin Matuska# Security Policy 2*22649d4dSMartin Matuska 3*22649d4dSMartin Matuska## Reporting a Vulnerability 4*22649d4dSMartin Matuska 5*22649d4dSMartin MatuskaWe encourage responsible disclosure of security vulnerabilities. If you 6*22649d4dSMartin Matuskafind something suspicious, we encourage and appreciate your report. 7*22649d4dSMartin Matuska 8*22649d4dSMartin MatuskaThe preferred way to report a vulnerability is to use the 9*22649d4dSMartin Matuska**"Report a vulnerability"** button under the **Security** tab of the 10*22649d4dSMartin MatuskaOpenZFS GitHub repository. This creates a private communication channel 11*22649d4dSMartin Matuskabetween you and the maintainers, allowing us to review the report 12*22649d4dSMartin Matuskaconfidentially and respond as quickly as possible. 13*22649d4dSMartin Matuska 14*22649d4dSMartin MatuskaPlease include, if possible: 15*22649d4dSMartin Matuska 16*22649d4dSMartin Matuska- A clear description of the issue 17*22649d4dSMartin Matuska- Steps to reproduce the problem 18*22649d4dSMartin Matuska- Affected versions or branches 19*22649d4dSMartin Matuska- Any proof of concept, logs, or screenshots 20*22649d4dSMartin Matuska- Your assessment of the potential impact 21*22649d4dSMartin Matuska 22*22649d4dSMartin Matuska## What to Expect 23*22649d4dSMartin Matuska 24*22649d4dSMartin Matuska- We will review security reports as soon as practical. 25*22649d4dSMartin Matuska- We may ask follow-up questions to better understand the issue. 26*22649d4dSMartin Matuska- Please allow time for investigation and coordination before public 27*22649d4dSMartin Matuska disclosure. 28*22649d4dSMartin Matuska- If the issue is confirmed, we will work on a fix and release a security 29*22649d4dSMartin Matuska update as needed for supported OpenZFS versions. 30