Vulnerability Management and Incident Response Policy
1. Reporting
- Report security vulnerabilities via email to osbuilders@redhat.com.
- Do not open public issues or submit public pull requests for undisclosed security vulnerabilities.
- Include a technical description, steps to reproduce, a proof of concept (if available), and the suspected impact.
2. Triage and Response
- The core maintainer team will acknowledge receipt of the vulnerability report within 72 hours.
- The incident response team will assign a severity level during triage.
- The reporter may receive status updates weekly through the email address used to report the vulnerability.
3. Public Disclosure
- Public disclosure occurs strictly after a patch is released and integrated into the primary branch.
- A CVE identifier will be requested when appropriate.
- The reporter will be credited in the public security advisory and release notes unless anonymity is explicitly requested.