If you discover a security vulnerability in RamaLama, please report it through GitHub's Security Advisory system. This allows us to coordinate a fix and disclosure process that protects users.
Please DO NOT report the issue publicly via the GitHub issue tracker, mailing list, or IRC. Please do not create a public issue.
- Go to our security advisory page to privately report the vulnerability.
- Provide detailed information about the vulnerability, including:
- Title: A concise, descriptive summary of the issue.
- Reporter Details: Your name/handle and affiliation.
- Technical Description: Detailed information regarding the vulnerability.
- Affected Versions: The specific version(s) or range(s) of software tested.
- Reproduction Steps: A minimal, functional example to reproduce the issue.
- Impact Assessment: Potential exploit scenarios and perceived severity. (optional)
- Suggested Fix: Any proposed patches or mitigations (optional).
- Disclosure Status: Whether this has been shared with other parties or published and your plan for future sharing (e.g., at a conference).
Your report will be reviewed by the maintainers, and we will work with you to understand and address the issue promptly.
We aim to provide an initial acknowledgement of your report within 48 hours.
Our goal is to assess the report, coordinate fix and disclosure as quickly as possible. All confirmed security vulnerabilities and incidents will be addressed according to severity level and impact on the project.
Any vulnerability information shared with core maintainers stays within a Containers project and will not be disseminated to other projects unless it is necessary to get the issue fixed.
As the security issue moves from triage, to an identified fix, to release planning, the core maintainers will keep the reporter updated.
We regularly perform patch releases for the supported latest version, which contains fixes for relevant security vulnerabilities and important bugs. Ramalama does not create or maintain historical release branches or backport security fixes to prior versions.
Direct all security questions and vulnerability reports to the security advisory page
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
- Updates: We will keep you informed about our progress in addressing the vulnerability
- Credit: We will credit you for the discovery when we publish the fix (unless you prefer to remain anonymous)
Thank you for helping keep RamaLama and its users secure!
This project is stewarded by Red Hat, Inc., an open source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847). Contact: cra-steward@redhat.com
Refer to Red Hat's security practices and vulnerability management policy for detailed information.