| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This document specifies the security process for the SwiftNIO project.
The SwiftNIO core team will address security vulnerabilities in all SwiftNIO 2.x versions. Since support for some Swift versions was dropped during the lifetime of SwiftNIO 2, patch releases will be created for the last supported SwiftNIO versions that supported older Swift versions. If a hypothetical security vulnerability was introduced in 2.10.0, then SwiftNIO core team would create the following patch releases:
SwiftNIO 1.x is considered end of life and will not receive any security patches.
If you believe that you have discovered a security or privacy vulnerability in our open source software, please report it to us using the GitHub private vulnerability feature. Reports should include specific product and software version(s) that you believe are affected; a technical description of the behavior that you observed and the behavior that you expected; the steps required to reproduce the issue; and a proof of concept or exploit.
The project team will do their best to acknowledge receiving all security reports within 7 days of submission. This initial acknowledgment is neither acceptance nor rejection of your report. The project team may come back to you with further questions or invite you to collaborate while working through the details of your report.
Keep these additional guidelines in mind when submitting your report:
While we welcome reports for open source software projects, they are not eligible for Apple Security Bounties.
| Back | FazBrowse Home | New Git URL |