Skip to content

Commit e86ba2b

Browse files
Add community/third-party apps note to security policy
Just making it match the new global one in nextcloud/.github#241 Signed-off-by: Josh Richards <josh.t.richards@gmail.com>
1 parent e98be0a commit e86ba2b

1 file changed

Lines changed: 12 additions & 9 deletions

File tree

SECURITY.md

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
# Security Policy
22

3-
[Security](https://nextcloud.com/security/) is very important to us.
3+
[Security](https://nextcloud.com/security/) is very important to us.
44

5-
If you believe you have found a security vulnerability that meets our definition of a security
5+
If you believe you have found a security vulnerability that meets our definition of a security
66
vulnerability, please report is as described below.
77

88
## Context
99

10-
Please review our [threat model and accepted risks](https://nextcloud.com/security/threat-model) to learn what
11-
is currently considered a security vulnerability versus expected behavior. And review what is considered
10+
Please review our [threat model and accepted risks](https://nextcloud.com/security/threat-model) to learn what
11+
is currently considered a security vulnerability versus expected behavior. And review what is considered
1212
[in scope or bounty eligible](https://hackerone.com/nextcloud/policy_scopes).
1313

1414

@@ -31,13 +31,17 @@ Your report should include:
3131

3232
You should receive an initial acknowledgement within 24 hours in most cases.
3333

34-
A member of the security team will confirm the vulnerability, determine its impact, follow-up with any questions,
34+
A member of the security team will confirm the vulnerability, determine its impact, follow-up with any questions,
3535
and coordinate the fix and publication.
3636

3737
The fix will be applied to all applicable and still supported stable branches, tested, and packaged in the next security release.
3838
The vulnerability will be publicly announced after the release. Finally, your name will be added
39-
to the [hall of fame](https://hackerone.com/nextcloud/thanks) as a thank you from the entire Nextcloud
40-
community.
39+
to the [hall of fame](https://hackerone.com/nextcloud/thanks) as a thank you from the entire Nextcloud
40+
community.
41+
42+
If the vulnerability involves an app that is not maintained by Nextcloud (i.e. hosted by the
43+
Nextcloud project but community maintained, or hosted elsewhere), the security team will try to coordinate with the
44+
current maintainer and help to get the issue fixed in similar fashion.
4145

4246
### Bug Bounties
4347

@@ -47,8 +51,7 @@ on past bounty ranges can be found at [hackerone.com/nextcloud](https://hackeron
4751
## Existing Security Advisories
4852

4953
Published security advisories for the Nextcloud Server, Clients and Apps can be viewed at
50-
[https://github.com/nextcloud/security-advisories/security/advisories](https://github.com/nextcloud/security-advisories/security/advisories
51-
).
54+
[https://github.com/nextcloud/security-advisories/security/advisories](https://github.com/nextcloud/security-advisories/security/advisories).
5255

5356
## Supported Versions
5457

0 commit comments

Comments
 (0)