Skip to content

Security: jonesdevelopment/sonar

.github/SECURITY.md

Reporting a security vulnerability

If you encounter a bug, issue, or vulnerability that doesn't pose an immediate security risk, you can report it through the regular issue tracker.

If you discover a security vulnerability within Sonar, please follow these steps to report it:

  1. Do not disclose serious issues publicly before they are fixed.
  2. Please provide as much detail as possible about the vulnerability.
  3. Depending on the severity and complexity of the issue, the response time may vary.
  4. Additional information might be requested.
  5. Once the vulnerability is confirmed, an update with the fixes will roll out.
  6. Users will be notified some time later to ensure safety for those who are using a vulnerable version.
  7. You will be publicly acknowledged for your contribution if you choose to be credited.

Contact

If you have any questions or concerns regarding the security of this project, please open a ticket on Discord or contact me via email at [email protected].

Acknowledgments

There aren’t any published security advisories