Skip to content

Security: fwdcloudsec/granted

SECURITY.md

Security Policy

Granted is maintained by fwdcloudsec. Full security documentation, including our release verification process and signing keys, is available at https://docs.granted.dev/security.

Reporting a vulnerability

Please report security vulnerabilities through GitHub private vulnerability reporting. This creates a private advisory that is only visible to you and the Granted maintainers.

Please do not report security vulnerabilities through public GitHub issues.

If you are unable to use GitHub, you can email granted-support@fwdcloudsec.org instead.

When reporting, please include as much of the following as you can:

  • The version of Granted affected
  • Steps to reproduce the issue
  • The potential impact of the vulnerability
  • Any suggested remediation

Coordinated vulnerability disclosure

We follow a coordinated vulnerability disclosure process, aligned with the requirements of the EU Cyber Resilience Act:

  • We aim to acknowledge your report within 5 business days.
  • We will investigate, keep you informed of progress, and work with you on remediation.
  • We will remediate confirmed vulnerabilities without undue delay and distribute security fixes free of charge through our standard release channels.
  • Once a fix is available, we will publish a GitHub Security Advisory describing the vulnerability, its severity and impact, and the fixed versions, and request a CVE where appropriate.
  • We ask that you do not publicly disclose the vulnerability until a fix has been released.

We do not currently operate a bug bounty program, but reporters may be acknowledged in security advisories as appropriate.

There aren't any published security advisories