模极社社区 - 制造业全产业链交流平台

    • 登录
    • 版块
    • 最新
    • 话题
    • 热门
    • 用户
    • 群组

    Incident Response Process for **resolve**

    社区公告
    1
    1
    0
    正在加载更多帖子
    • 从旧到新
    • 从新到旧
    • 最多赞同
    回复
    • 在新帖中回复
    登录后回复
    此主题已被删除。只有拥有主题管理权限的用户可以查看。
    • S
      system 2 最后由 编辑

      <h2>Incident Response Process for resolve</h2>

      <h3>Reporting a Vulnerability</h3>

      <p>We take the security of <strong>resolve</strong> very seriously. If you believe you’ve found a security vulnerability, please inform us responsibly through coordinated disclosure.</p>

      <h4>How to Report</h4>

      <blockquote>
      <p><strong>Do not</strong> report security vulnerabilities through public GitHub issues, discussions, or social media.</p>
      </blockquote>

      <p>Instead, please use one of these secure channels:</p>

      <ol>
      <li><strong>GitHub Security Advisories</strong></li>
      </ol>
      <p> Use the <strong>Report a vulnerability</strong> button in the Security tab of the <a href="https://github.com/browserify/resolve">browserify/resolve repository</a>.</p>

      <ol>
      <li><strong>Email</strong></li>
      </ol>
      <p> Follow the posted <a href="https://github.com/browserify/resolve/security/policy">Security Policy</a>.</p>

      <h4>What to Include</h4>

      <p><strong>Required Information:</strong></p>
      <ul>
      <li>Brief description of the vulnerability type</li>
      <li>Affected version(s) and components</li>
      <li>Steps to reproduce the issue</li>
      <li>Impact assessment (what an attacker could achieve)</li>
      <li>Confirm the issue is not present in test files (in other words, only via the official entry points in <code>exports</code>)</li>
      </ul>

      <p><strong>Helpful Additional Details:</strong></p>
      <ul>
      <li>Full paths of affected source files</li>
      <li>Specific commit or branch where the issue exists</li>
      <li>Required configuration to reproduce</li>
      <li>Proof-of-concept code (if available)</li>
      <li>Suggested mitigation or fix</li>
      </ul>

      <h3>Our Response Process</h3>

      <p><strong>Timeline Commitments:</strong></p>
      <ul>
      <li><strong>Initial acknowledgment</strong>: Within 24 hours</li>
      <li><strong>Detailed response</strong>: Within 3 business days</li>
      <li><strong>Status updates</strong>: Every 7 days until resolved</li>
      <li><strong>Resolution target</strong>: 90 days for most issues</li>
      </ul>

      <p><strong>What We’ll Do:</strong></p>
      <ol>
      <li>Acknowledge your report and assign a tracking ID</li>
      <li>Assess the vulnerability and determine severity</li>
      <li>Develop and test a fix</li>
      <li>Coordinate disclosure timeline with you</li>
      <li>Release a security update and publish an advisory and CVE</li>
      <li>Credit you in our security advisory (if desired)</li>
      </ol>

      <h3>Disclosure Policy</h3>

      <ul>
      <li><strong>Coordinated disclosure</strong>: We’ll work with you on timing</li>
      <li><strong>Typical timeline</strong>: 90 days from report to public disclosure</li>
      <li><strong>Early disclosure</strong>: If actively exploited</li>
      <li><strong>Delayed disclosure</strong>: For complex issues</li>
      </ul>

      <h3>Scope</h3>

      <p><strong>In Scope:</strong></p>
      <ul>
      <li><strong>resolve</strong> package (all supported versions)</li>
      <li>Official examples and documentation</li>
      <li>Core resolution APIs</li>
      <li>Dependencies with direct security implications</li>
      </ul>

      <p><strong>Out of Scope:</strong></p>
      <ul>
      <li>Third-party wrappers or extensions</li>
      <li>Bundler-specific integrations</li>
      <li>Social engineering or physical attacks</li>
      <li>Theoretical vulnerabilities without practical exploitation</li>
      <li>Issues in non-production files</li>
      </ul>

      <h3>Security Measures</h3>

      <p><strong>Our Commitments:</strong></p>
      <ul>
      <li>Regular vulnerability scanning via <code>npm audit</code></li>
      <li>Automated security checks in CI/CD (GitHub Actions)</li>
      <li>Secure coding practices and mandatory code review</li>
      <li>Prompt patch releases for critical issues</li>
      </ul>

      <p><strong>User Responsibilities:</strong></p>
      <ul>
      <li>Keep <strong>resolve</strong> updated</li>
      <li>Monitor dependency vulnerabilities</li>
      <li>Follow secure configuration guidelines for module resolution</li>
      </ul>

      <h3>Legal Safe Harbor</h3>

      <p><strong>We will NOT:</strong></p>
      <ul>
      <li>Initiate legal action</li>
      <li>Contact law enforcement</li>
      <li>Suspend or terminate your access</li>
      </ul>

      <p><strong>You must:</strong></p>
      <ul>
      <li>Only test against your own installations</li>
      <li>Not access, modify, or delete user data</li>
      <li>Not degrade service availability</li>
      <li>Not publicly disclose before coordinated disclosure</li>
      <li>Act in good faith</li>
      </ul>

      <h3>Recognition</h3>

      <ul>
      <li><strong>Advisory Credits</strong>: Credit in GitHub Security Advisories (unless anonymous)</li>
      </ul>

      <h3>Security Updates</h3>

      <p><strong>Stay Informed:</strong></p>
      <ul>
      <li>Subscribe to npm updates for <strong>resolve</strong></li>
      <li>Enable GitHub Security Advisory notifications</li>
      </ul>

      <p><strong>Update Process:</strong></p>
      <ul>
      <li>Patch releases (e.g., 1.22.10 → 1.22.11)</li>
      <li>Out-of-band re</li>
      </ul>

      <hr>
      <p>你在实际生产中遇到过类似问题吗?欢迎留言讨论。</p>

      1 条回复 最后回复 回复 引用 0
      • First post
        Last post
      Powered by NodeBB | Contributors