Skip to content

Security: undp/national-climate-transparency

Security

SECURITY.md

๐Ÿ›ก๏ธ Security Policy

๐ŸŒ Supported Versions

This is the list of versions of carbon-registry which are currently being supported with security updates.

Version Supported
1.x โœ…
0.x โŒ

๐Ÿšจ Reporting a Vulnerability

The United Nations Development Programme (UNDP) takes the security of our software products seriously. If you believe you have found a security vulnerability in the Carbon Registry AGPL software, please report it to us as described below.

๐Ÿ“ฎ How to Report a Vulnerability

  1. ๐Ÿ”’ Do Not Report Security Vulnerabilities Publicly

    • Please do not report security vulnerabilities through public GitHub issues.
  2. ๐Ÿ“ง Email

    • Directly email the UNDP Carbon Registry security team at [email protected].
    • Please provide detailed information about the vulnerability, including steps to reproduce, potential impact, and suggested mitigation or remediation if known.
  3. ๐Ÿ•’ Expect a Response

    • We strive to acknowledge receipt of vulnerabilities and communicate our intended timeline for a fix within days.

๐Ÿ“ข Disclosure Policy

  1. ๐Ÿค Confidentiality

    • Reporters of security vulnerabilities are expected to keep the vulnerability details confidential until a fix is released.
  2. ๐Ÿ“ฃ Public Disclosure

    • Details about the vulnerability, including a description, its impact, and the date the fix was released, may be published after a fix is released, allowing users to assess the impact on their own deployment and take appropriate measures. Reporter is kept confidential unless otherwise requested.

๐Ÿ” Security-Related Configuration and Compliance

Please refer to the documentation for information on secure configuration and deployment and compliance with security standards and best practices.

๐Ÿ’ฌ Comments on this Policy

If you have suggestions on how this process could be improved, please submit a pull request.

๐Ÿ™ Acknowledgements

The Standard Carbon Registry team would like to thank all security researchers who responsibly disclose vulnerabilities and help us keep our users safe.

There arenโ€™t any published security advisories