Skip to main content

Vulnerability Management and Incident Response Policy

1. Reporting

  • Report security vulnerabilities via email to osbuilders@redhat.com.
  • Do not open public issues or submit public pull requests for undisclosed security vulnerabilities.
  • Include a technical description, steps to reproduce, a proof of concept (if available), and the suspected impact.

2. Triage and Response

  • The core maintainer team will acknowledge receipt of the vulnerability report within 72 hours.
  • The incident response team will assign a severity level during triage.
  • The reporter may receive status updates weekly through the email address used to report the vulnerability.

3. Public Disclosure

  • Public disclosure occurs strictly after a patch is released and integrated into the primary branch.
  • A CVE identifier will be requested when appropriate.
  • The reporter will be credited in the public security advisory and release notes unless anonymity is explicitly requested.