Skip to content

Security: DefectDojo/django-DefectDojo

Security Navigation

SECURITY.md

Security

No technology is perfect, and we believe that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in DefectDojo, we encourage you to notify us. We welcome working with you to resolve the issue promptly.

Disclosure Policy and Process

  • Let us know by submitting the finding through our HackerOne disclosure submission program as soon as possible, upon discovery of a potential security issue.
  • Once we've assessed your HackerOne report, a member of our team will create a GitHub "security advisory", which will allow the reporter and the DefectDojo team to work on the issue in a confidential manner. We will invite you as a collaborator to the advisory and any needed trusted persons.
  • That "security advisory" will also allow us to have a temporary private fork, to work on the fix in confidentiality.
  • Once a fix is ready, we will include the fix in our next release and mark that release as a security release.
  • Details on the issue will be embargoed for 30 days to give users an oppurtunity to upgrade, after which we will coordinate disclosure with the researcher(s).
  • If you've contributed the fix, you will be credited for it.

Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Denial of service
  • Spamming
  • Social engineering (including phishing) of DefectDojo staff or contractors
  • Any physical attempts against DefectDojo property or cloud hosted environments

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep DefectDojo and our users safe!