Skip to content

Security: vbudko/EVerest

Security

SECURITY.md

Security Policy

Supported Versions

Since the beginning of 2023 we are releasing versions of EVerest in a monthly cadence, the specifics of this release process are outlined in RELEASE.md.

At the moment we only support the most recent release of EVerest with (security) updates.

Version Supported
2023.3.0
2023.2.1
2023.2.0
2023.1.0

Reporting a Vulnerability

If you found a vulnerability, we are super keen and grateful to get the details. Please use this private mailing list to let us know: https://lists.lfenergy.org/g/everest-tsc

Please DON'T use the publicly visible issue reporting functionality from github!

We try to monitor this list and respond every working day, but in in initial respond time should not go beyond 7 days. Please provide us with your estimation of the severity of your finding. Every other information on how to exploit it as well as everything else you could provide is helpful, please also orient yourself on our questionary for non security related issue reporting: https://github.com/EVerest/everest/issues/new?assignees=&labels=&template=bug_report.md&title=

There aren’t any published security advisories