Security

How to report a vulnerability, what happens next, and how fixes reach you.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues. Send an email to support@projectsveltos.io. The policy covers all repositories under the projectsveltos GitHub organization. Please include, as far as you can:

  • A description of the vulnerability and its potential impact
  • The affected components and versions
  • Steps to reproduce the issue
  • Proof-of-concept code, if you have it
  • Suggested remediation, if any

What happens next

  1. 01

    Acknowledgement

    You receive an acknowledgement within 2 business days.

  2. 02

    Investigation

    We investigate and keep you informed of progress.

  3. 03

    Fix and release

    Once the issue is confirmed, we work on a fix and coordinate a release.

  4. 04

    Disclosure

    We disclose publicly after a fix is available, and credit you unless you prefer to remain anonymous.

Supported versions

Community security fixes are released for the latest minor version, and we encourage everyone to stay on the latest release.

Enterprise customers

When a CVE affects your deployment, Enterprise customers receive a patched image directly, ahead of the next scheduled release, with direct engineering access for urgent issues.

See Enterprise plans