@@ -3,14 +3,14 @@ SPDX-FileCopyrightText: 2021-2024 Nextcloud GmbH and Nextcloud contributors
33SPDX-License-Identifier: MIT
44-->
55
6- # Security Policy
6+ # Security Policy
77
88## 💡 TLDR: Report security issues at [ hackerone.com/nextcloud] ( https://hackerone.com/nextcloud )
99
1010### Found a security bug in Nextcloud? Let's get it fixed!
1111
12- If you believe you have found an issue that meets our
13- [ definition of a security vulnerability] ( https://nextcloud.com/security/threat-model ) ,
12+ If you believe you have found an issue that meets our
13+ [ definition of a security vulnerability] ( https://nextcloud.com/security/threat-model ) ,
1414we encourage you to let us know right away. Please use the reporting process described below.
1515
1616| If you are a... | See section... |
@@ -36,8 +36,8 @@ Your report should include:
3636
3737If you require encrypted communication, please request it in your initial message.
3838
39- > ** Note:** This process is for confidential reporting of software vulnerabilities only.
40- > For general support or configuration help, see
39+ > ** Note:** This process is for confidential reporting of software vulnerabilities only.
40+ > For general support or configuration help, see
4141> [ Nextcloud Support] ( https://nextcloud.com/support/ ) .
4242
4343## What to Expect After Reporting
@@ -50,42 +50,42 @@ A member of our security team will:
5050- Follow up with any questions
5151- Coordinate the fix and public disclosure
5252
53- We apply, test, and release fixes for all relevant, supported stable branches in the next
54- security update. Vulnerabilities are publicly announced after the fix is released. As a thank
53+ We apply, test, and release fixes for all relevant, supported stable branches in the next
54+ security update. Vulnerabilities are publicly announced after the fix is released. As a thank
5555you, we will add your name to our [ Hall of Fame] ( https://hackerone.com/nextcloud/thanks ) .
5656
57- If your report concerns an app not maintained by Nextcloud (e.g., community-maintained apps
58- hosted by Nextcloud or hosted elsewhere), our security team will coordinate with the current
57+ If your report concerns an app not maintained by Nextcloud (e.g., community-maintained apps
58+ hosted by Nextcloud or hosted elsewhere), our security team will coordinate with the current
5959maintainer to help resolve the issue in a similar fashion.
6060
6161## Bug Bounties
6262
63- If you are interested in a bug bounty, please note that complete, detailed reports can
64- contribute to higher bounty awards. Details on past bounties are available at
63+ If you are interested in a bug bounty, please note that complete, detailed reports can
64+ contribute to higher bounty awards. Details on past bounties are available at
6565[ HackerOne] ( https://hackerone.com/nextcloud ) .
6666
6767## Security Advisories
6868
69- Published advisories for Nextcloud Server, Clients, and Apps are available at the
70- [ Nextcloud Security Advisories] ( https://github.com/nextcloud/security-advisories/security/advisories )
69+ Published advisories for Nextcloud Server, Clients, and Apps are available at the
70+ [ Nextcloud Security Advisories] ( https://github.com/nextcloud/security-advisories/security/advisories )
7171page.
7272
7373## Supported Versions
7474
75- Each major release of Nextcloud Server receives security updates for one year from its
76- initial release date. The Nextcloud project typically supports at least the two most recent
75+ Each major release of Nextcloud Server receives security updates for one year from its
76+ initial release date. The Nextcloud project typically supports at least the two most recent
7777major releases.
7878
7979To stay protected:
8080- Ensure your Nextcloud Server is always running a supported major release
81- - Promptly apply all maintenance releases (these include critical security and functionality
81+ - Promptly apply all maintenance releases (these include critical security and functionality
8282 bug fixes)
83- - Monitor the end-of-life (EOL) date for your major release (after this date, no further
84- maintenance releases will be published. Upgrading to a newer major release is strongly
83+ - Monitor the end-of-life (EOL) date for your major release (after this date, no further
84+ maintenance releases will be published. Upgrading to a newer major release is strongly
8585 recommended.)
8686
87- See the
88- [ Maintenance and Release Schedule] ( https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule )
87+ See the
88+ [ Maintenance and Release Schedule] ( https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule )
8989for details.
9090
9191---
0 commit comments