For all WasmEdge security-related defects, please send an email to [email protected]. You will receive an acknowledgement mail within 24 hours. After that, we will give a detailed response about the subsequent process within 48 hours. Please do not submit security vulnerabilities directly as Github Issues.
For known public security vulnerabilities, we will disclose the disclosure as soon as possible after receiving the report. Vulnerabilities discovered for the first time will be disclosed in accordance with the following process:
- The received security vulnerability report shall be handed over to the security team for follow-up coordination and repair work.
- After the vulnerability is confirmed, we will create a draft Security Advisory on Github that lists the details of the vulnerability.
- Invite related personnel to discuss about the fix.
- Fork the temporary private repository on Github, and collaborate to fix the vulnerability.
- After the fix code is merged into all supported versions, the vulnerability will be publicly posted in the GitHub Advisory Database.