Skip to main content

Vulnerability Management and Incident Response Policy

For a quick overview of how to report vulnerabilities, see the organization-wide SECURITY.md file, which applies to all repositories under the osbuild GitHub organization.

1. Reporting

  • Report security vulnerabilities via email to osbuilders@redhat.com.
  • Do not open public issues or submit public pull requests for undisclosed security vulnerabilities.
  • Include a technical description, steps to reproduce, a proof of concept (if available), and the suspected impact.

2. Triage and Response

  • The core maintainer team will acknowledge receipt of the vulnerability report within 72 hours.
  • The incident response team will assign a severity level during triage.
  • The reporter may receive status updates weekly through the email address used to report the vulnerability.

3. Public Disclosure

  • Public disclosure occurs strictly after a patch is released and integrated into the primary branch.
  • A CVE identifier will be requested when appropriate.
  • The reporter will be credited in the public security advisory and release notes unless anonymity is explicitly requested.

4. EU Cyber Resilience Act

This project is stewarded by Red Hat, Inc., an open source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847). Contact: cra-steward@redhat.com

If you become aware of an actively exploited vulnerability or a severe incident affecting this project, please report it promptly — see Reporting Actively Exploited Vulnerabilities and Severe Incidents for the process and timelines.

For Red Hat's general security practices, see Red Hat Product Security.