keycloak-scim/SECURITY.md

30 lines
1.7 KiB
Markdown
Raw Normal View History

2020-04-30 08:46:49 +00:00
# Security Policy
2021-11-11 09:06:36 +00:00
The Keycloak team takes security very seriously, and aim to resolve issues as quickly as possible. Building secure
software is a continuous process, and can always be improved. As such we welcome reports on potential security
vulnerabilities, as well as suggestions around hardening the software and our process.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
## Reporting a suspected vulnerability
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
It is important that suspected vulnerabilities are disclosed in a responsible way, and are not publicly disclosed until
after they have been analysed and a fix is available.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
To report a security vulnerability, send an email to keycloak-security@googlegroups.com.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
If you would like to work with us on a fix for the security vulnerability, please include your GitHub username
in the above email, and we will provide you access to a temporary private fork where we can collaborate on a fix
without it being disclosed publicly.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
Do *not* open a public issue, send a pull request, or disclose any information about the suspected vulnerability publicly.
If you discover any publicly disclosed security vulnerabilities, please notify us *immediately* through
keycloak-security@googlegroups.com.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
## Supported Versions
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
Depending on the severity of a vulnerability the issue may be fixed in the current `major.minor` release of Keycloak, or
for lower severity vulnerabilities or hardening in the following `major.minor` release. Refer to
`https://www.keycloak.org/downloads` to find the latest release.
2020-04-30 08:46:49 +00:00
2021-11-11 09:06:36 +00:00
If you are unable to regularly upgrade Keycloak we encourage you to consider
[Red Hat Single Sign-On](https://access.redhat.com/products/red-hat-single-sign-on), which offers
[long term support](https://access.redhat.com/support/policy/updates/jboss_notes#p_sso) of specific versions of Keycloak.