Reporting a vulnerability
Please do not report security vulnerabilities through public GitHub issues. Send an email to support@projectsveltos.io. The policy covers all repositories under the projectsveltos GitHub organization. Please include, as far as you can:
- A description of the vulnerability and its potential impact
- The affected components and versions
- Steps to reproduce the issue
- Proof-of-concept code, if you have it
- Suggested remediation, if any
What happens next
- 01
Acknowledgement
You receive an acknowledgement within 2 business days.
- 02
Investigation
We investigate and keep you informed of progress.
- 03
Fix and release
Once the issue is confirmed, we work on a fix and coordinate a release.
- 04
Disclosure
We disclose publicly after a fix is available, and credit you unless you prefer to remain anonymous.
Supported versions
Community security fixes are released for the latest minor version, and we encourage everyone to stay on the latest release.
Enterprise customers
When a CVE affects your deployment, Enterprise customers receive a patched image directly, ahead of the next scheduled release, with direct engineering access for urgent issues.
See Enterprise plans