Incident Response Process for **resolve**
-
<h2>Incident Response Process for resolve</h2>
<h3>Reporting a Vulnerability</h3>
<p>We take the security of <strong>resolve</strong> very seriously. If you believe you’ve found a security vulnerability, please inform us responsibly through coordinated disclosure.</p>
<h4>How to Report</h4>
<blockquote>
<p><strong>Do not</strong> report security vulnerabilities through public GitHub issues, discussions, or social media.</p>
</blockquote><p>Instead, please use one of these secure channels:</p>
<ol>
<li><strong>GitHub Security Advisories</strong></li>
</ol>
<p> Use the <strong>Report a vulnerability</strong> button in the Security tab of the <a href="https://github.com/browserify/resolve">browserify/resolve repository</a>.</p><ol>
<li><strong>Email</strong></li>
</ol>
<p> Follow the posted <a href="https://github.com/browserify/resolve/security/policy">Security Policy</a>.</p><h4>What to Include</h4>
<p><strong>Required Information:</strong></p>
<ul>
<li>Brief description of the vulnerability type</li>
<li>Affected version(s) and components</li>
<li>Steps to reproduce the issue</li>
<li>Impact assessment (what an attacker could achieve)</li>
<li>Confirm the issue is not present in test files (in other words, only via the official entry points in <code>exports</code>)</li>
</ul><p><strong>Helpful Additional Details:</strong></p>
<ul>
<li>Full paths of affected source files</li>
<li>Specific commit or branch where the issue exists</li>
<li>Required configuration to reproduce</li>
<li>Proof-of-concept code (if available)</li>
<li>Suggested mitigation or fix</li>
</ul><h3>Our Response Process</h3>
<p><strong>Timeline Commitments:</strong></p>
<ul>
<li><strong>Initial acknowledgment</strong>: Within 24 hours</li>
<li><strong>Detailed response</strong>: Within 3 business days</li>
<li><strong>Status updates</strong>: Every 7 days until resolved</li>
<li><strong>Resolution target</strong>: 90 days for most issues</li>
</ul><p><strong>What We’ll Do:</strong></p>
<ol>
<li>Acknowledge your report and assign a tracking ID</li>
<li>Assess the vulnerability and determine severity</li>
<li>Develop and test a fix</li>
<li>Coordinate disclosure timeline with you</li>
<li>Release a security update and publish an advisory and CVE</li>
<li>Credit you in our security advisory (if desired)</li>
</ol><h3>Disclosure Policy</h3>
<ul>
<li><strong>Coordinated disclosure</strong>: We’ll work with you on timing</li>
<li><strong>Typical timeline</strong>: 90 days from report to public disclosure</li>
<li><strong>Early disclosure</strong>: If actively exploited</li>
<li><strong>Delayed disclosure</strong>: For complex issues</li>
</ul><h3>Scope</h3>
<p><strong>In Scope:</strong></p>
<ul>
<li><strong>resolve</strong> package (all supported versions)</li>
<li>Official examples and documentation</li>
<li>Core resolution APIs</li>
<li>Dependencies with direct security implications</li>
</ul><p><strong>Out of Scope:</strong></p>
<ul>
<li>Third-party wrappers or extensions</li>
<li>Bundler-specific integrations</li>
<li>Social engineering or physical attacks</li>
<li>Theoretical vulnerabilities without practical exploitation</li>
<li>Issues in non-production files</li>
</ul><h3>Security Measures</h3>
<p><strong>Our Commitments:</strong></p>
<ul>
<li>Regular vulnerability scanning via <code>npm audit</code></li>
<li>Automated security checks in CI/CD (GitHub Actions)</li>
<li>Secure coding practices and mandatory code review</li>
<li>Prompt patch releases for critical issues</li>
</ul><p><strong>User Responsibilities:</strong></p>
<ul>
<li>Keep <strong>resolve</strong> updated</li>
<li>Monitor dependency vulnerabilities</li>
<li>Follow secure configuration guidelines for module resolution</li>
</ul><h3>Legal Safe Harbor</h3>
<p><strong>We will NOT:</strong></p>
<ul>
<li>Initiate legal action</li>
<li>Contact law enforcement</li>
<li>Suspend or terminate your access</li>
</ul><p><strong>You must:</strong></p>
<ul>
<li>Only test against your own installations</li>
<li>Not access, modify, or delete user data</li>
<li>Not degrade service availability</li>
<li>Not publicly disclose before coordinated disclosure</li>
<li>Act in good faith</li>
</ul><h3>Recognition</h3>
<ul>
<li><strong>Advisory Credits</strong>: Credit in GitHub Security Advisories (unless anonymous)</li>
</ul><h3>Security Updates</h3>
<p><strong>Stay Informed:</strong></p>
<ul>
<li>Subscribe to npm updates for <strong>resolve</strong></li>
<li>Enable GitHub Security Advisory notifications</li>
</ul><p><strong>Update Process:</strong></p>
<ul>
<li>Patch releases (e.g., 1.22.10 → 1.22.11)</li>
<li>Out-of-band re</li>
</ul><hr>
<p>你在实际生产中遇到过类似问题吗?欢迎留言讨论。</p>