Skip to content

Commit a446d16

Browse files
padovanpatersonc
authored andcommitted
docs: add security policy and vulnerability reporting page
Signed-off-by: Gustavo Padovan <[email protected]>
1 parent a4f34dd commit a446d16

File tree

1 file changed

+84
-0
lines changed

1 file changed

+84
-0
lines changed
Lines changed: 84 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,84 @@
1+
---
2+
title: "Security"
3+
date: 2025-01-09
4+
description: "Security policy and vulnerability reporting for KernelCI"
5+
weight: 50
6+
---
7+
8+
## Security Policy
9+
10+
KernelCI is committed to maintaining the security and integrity of our infrastructure and services. We take security vulnerabilities seriously and appreciate the efforts of security researchers and community members who help us maintain a secure platform.
11+
12+
## Reporting Security Vulnerabilities
13+
14+
If you discover a security vulnerability in any KernelCI project, please report it responsibly by emailing:
15+
16+
17+
18+
When reporting a vulnerability, please include:
19+
20+
- A detailed description of the vulnerability
21+
- Steps to reproduce the issue
22+
- Potential impact assessment
23+
- Any suggested remediation steps (if available)
24+
- Your contact information for follow-up questions
25+
26+
## Response Process
27+
28+
Once a security report is received:
29+
30+
1. The KernelCI system administration team will acknowledge receipt
31+
2. The team will investigate and assess the severity of the reported issue
32+
3. We will work on a fix and coordinate disclosure timeline with the reporter
33+
4. Once resolved, we will publish appropriate security advisories
34+
35+
## Scope
36+
37+
Security reports should focus on vulnerabilities in:
38+
39+
- KernelCI infrastructure and services
40+
- KernelCI web applications (Dashboard, API, etc.)
41+
- KernelCI tools and command-line utilities
42+
- Authentication and authorization mechanisms
43+
- Data exposure or privacy issues
44+
45+
## Bug Bounty Program
46+
47+
**KernelCI does not currently offer a bug bounty program or monetary rewards for security vulnerability reports.**
48+
49+
We greatly appreciate responsible disclosure and will publicly acknowledge security researchers who report valid vulnerabilities (unless they prefer to remain anonymous).
50+
51+
## Security Best Practices
52+
53+
For KernelCI contributors and users:
54+
55+
- Keep your API tokens and credentials secure
56+
- Use strong authentication methods
57+
- Report suspicious activity to the sysadmin team
58+
- Follow secure coding practices when contributing code
59+
- Regularly update dependencies and tools
60+
61+
## Public Disclosure
62+
63+
We request that security researchers:
64+
65+
- Provide us reasonable time to address vulnerabilities before public disclosure
66+
- Avoid accessing, modifying, or deleting data that does not belong to you
67+
- Do not perform testing that could degrade or disrupt KernelCI services
68+
- Limit testing to your own accounts or test data when possible
69+
70+
Thank you for helping keep KernelCI and the Linux kernel testing community secure.
71+
72+
73+
## Out of Scope
74+
75+
**KernelCI is not responsible for security issues in the Linux kernel itself or in projects we test.**
76+
77+
Do not report to KernelCI:
78+
79+
- **Linux kernel vulnerabilities** - Report these to the kernel community by following their [security process](https://docs.kernel.org/process/security-bugs.html)
80+
- **Vulnerabilities in upstream projects** being tested by KernelCI (e.g., specific kernel trees, bootloaders, etc.) - Report these directly to the respective upstream project maintainers
81+
- **Hardware security issues** - Contact the hardware vendor directly
82+
- **Issues with test results or CI failures** - These are not security vulnerabilities; please use regular bug reporting channels
83+
84+
KernelCI provides testing infrastructure and tooling. We test the Linux kernel and related projects but are not responsible for security issues found within the code being tested.

0 commit comments

Comments
 (0)