Skip to content

Security: Ericsson/xcm

SECURITY.md

Security Policy

If you believe you have found a security vulnerability in an Ericsson-managed repository, please report it to us as described below.

Reporting a vulnerability

Please do not open a public issue, pull request, or discussion for a security problem.

Instead, use the "Report a vulnerability" button on this repository's Security tab. This keeps the report private, lets us collaborate with you on a draft advisory, and supports private patch development.

What to include

  • Affected project, component, and version(s)
  • Environment (OS, architecture, platform, configuration)
  • Reproduction steps; proof-of-concept or screenshots if available
  • Impact and how the issue could be exploited
  • Any embargo/disclosure timing you would like us to honor
  • Whether and how you wish to be credited

Supported Versions

The default policy for projects hosted on Ericsson's GitHub organization is to support security updates for the latest release. This means security fixes will not be backported to older versions.

You may of course still report vulnerabilities on older versions.

Some projects may use a different policy, as described in their dedicated SECURITY.md file.

Archived repositories are not supported and do not receive security updates anymore.

Scope

This file documents the general Security Policy for Ericsson-managed repositories hosted on GitHub. It is the default for all projects which do not have a project-specific policy. Project-specific policies are documented in SECURITY.md files located at the root of a given repository. These policies have a repository-specific scope and override this general policy.

You can find this general policy in the .github repository of this organization.

There aren't any published security advisories