Skip to content

Security: conforma/user-guide

SECURITY.md

Reporting a Security Vulnerability or Incident for Conforma

To report a security issue, please click on the "Report a vulnerability" button from the "Security" tab.

To help us triage and resolve the issue efficiently, please follow the instructions for Privately reporting a security vulnerability.

If the issue is confirmed as a vulnerability, we will open a Security Advisory. We will fully acknowledge the reporter for responsibly disclosing the vulnerability.

Response Timeline

The maintainers will respond within 3 working days of the report.

Security Policy

Full details of Red Hat’s security disclosure and remediation process can be found here: https://access.redhat.com/articles/red-hat-coordinated-vulnerability-disclosure

EU Cyber Resilience Act — Open Source Steward Statement

This project is stewarded by Red Hat, Inc., an open source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847). Contact: cra-steward@redhat.com

Refer to Red Hat's security practices and vulnerability management policy for detailed information.

There aren't any published security advisories