| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This document outlines the security practices and incident response procedures followed by the Mockoon team to ensure the safety and integrity of our open-source applications. This policy does not cover our cloud services, which have their own dedicated security measures and protocols.
Please do not report security vulnerabilities through public GitHub issues.
To report a vulnerability in Mockoon's desktop application or packages (CLI, serverless, etc.) please send an email to security@mockoon.com. You should receive a response from us within 48 hours.
Please include the requested information listed below to help us better understand the nature and scope of the possible issue:
This document outlines the process the Mockoon team follows when handling security vulnerabilities reported in our open-source applications and libraries (CLI, etc.). Our goal is to be transparent with our community about how we triage, fix, and disclose security issues.
This process applies only to the open-source tools maintained by the Mockoon team not the Cloud services.
This initial phase begins when we receive a security vulnerability report. The primary goal is to understand, reproduce, and assess the potential impact of the reported issue.
Process Overview:
When a report is received, a designated security lead from the core team will:
Once a vulnerability is confirmed, our focus shifts to fixing the issue and preventing potential exploitation.
Process Overview:
Our remediation efforts include the following steps:
During this phase, we analyze the codebase to understand the full scope of the vulnerability.
Process Overview:
The team will perform an analysis to determine:
Transparency with our users is critical. This phase is about communicating the vulnerability and its solution to the community in a clear and timely manner.
Process Overview:
Following the release of a patched version, we will execute our public disclosure process.
Publish Security Advisory: We will publish a detailed security advisory on GitHub. This advisory will serve as the single source of truth and will contain:
Community Communication: We will announce the security patch through our public channels, including the application's release notes and our blog, directing users to the official GitHub Security Advisory for details.
| Back | FazBrowse Home | New Git URL |