frostfs.info/content/about/security.md
Vitaliy Potyarkin c6c5e2a5f1
All checks were successful
build static site / build (pull_request) Successful in 23s
[#23] List primary communication channels
[interact]: https://www.bestpractices.dev/en/criteria/0?details=true&rationale=true#0.interact

Signed-off-by: Vitaliy Potyarkin <v.potyarkin@yadro.com>
2025-02-18 17:05:23 +03:00

30 lines
1.1 KiB
Markdown

---
title: Security policy
date: 2025-02-18
---
## How To Report a Vulnerability
If you think you have found a vulnerability in any FrostFS component, please
report it to us through coordinated disclosure.
Contact TrueCloudLab security team at
**[security@frostfs.info](mailto:security@frostfs.info)**
Please do not report security vulnerabilities through public issues,
discussions, or change requests.
Please include as much information as you can to help us better understand and resolve the issue:
- The type of issue (e.g., buffer overflow, or cross-site scripting)
- Affected components and their versions
- Impact of the issue, including how an attacker might exploit the issue
- Step-by-step instructions to reproduce the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Full paths of source file(s) related to the manifestation of the issue
- Any special configuration required to reproduce the issue
- Any log files that are related to this issue (if possible)
- Proof-of-concept or exploit code (if possible)
This information will help us triage your report more quickly.