Skip to content

Security: atirna/icalendar

Security

SECURITY.md

Security policy

This security policy describes how to privately report potential security issues with icalendar, and how the icalendar security team processes reports, all in a responsible manner. If you're unsure whether your issue qualifies as a security vulnerability, it's better to err on the side of caution and report it as one, allowing the icalendar security team to evaluate its merits and determine whether it's one.

Supported versions

Security vulnerabilities are fixed only for the latest version of icalendar. It is highly recommended to upgrade to the latest release.

Procedure

The icalendar security team will coordinate with the Plone security team.

If it's determined that your report may be a security vulnerability with the project, the team may contact you for further information. As volunteers, the team asks that you delay public disclosure of your report for at least ninety (90) days from the date you report it to the team. This will allow sufficient time for the team to process your report and coordinate disclosure with you.

Once verified and fixed, the following steps will be taken:

There aren't any published security advisories