This security policy applies to all repositories in the Packit organization on GitHub.
If you discover a potential security issue, let us know as soon as possible, and we will try to resolve the issue as quickly as possible.
To report a vulnerability, please use the Security Advisor Form. This provides a private communication channel between you and the maintainers.
Please include a clear description of the issue, an overview of the steps to reproduce the issue and the affected versions.
If you already identified a possible fix, please also include this in the form. This can greatly reduce the amount of time it takes to resolve the issue.
Please adhere to these guidelines when researching the security of Packit.
- Do not perform Denial of Service (DoS) attacks.
- Do not perform social engineering on one of the contributors, maintainers or users of Packit.
- Do not publicly disclose vulnerabilities before a fix is implemented in Packit.
- Avoid high volume or automated testing that impacts our service stability without prior approval from the maintainers.
- Limit testing to the minimum required to demonstrate the issue, and avoid actions that could impact availability or data integrity of our services.
- Adhere to the security guidelines of third-party projects, when the vulnerability involves such project.
Only the latest version is actively maintained and will receive security updates. We try to also fix major security issues for the most recent older versions, but this support is not guaranteed.