xref: /aosp_15_r20/external/jackson-databind/SECURITY.md (revision 0ed15c778abdfe0f5f51f6133673e1619d6e56e4)
1*0ed15c77SAndroid Build Coastguard Worker# Security Policy
2*0ed15c77SAndroid Build Coastguard Worker
3*0ed15c77SAndroid Build Coastguard WorkerLast Updated: 2019-11-26
4*0ed15c77SAndroid Build Coastguard Worker
5*0ed15c77SAndroid Build Coastguard Worker## Supported Versions
6*0ed15c77SAndroid Build Coastguard Worker
7*0ed15c77SAndroid Build Coastguard WorkerCurrent status of open branches, with new releases, can be found from [Jackson Releases](https://github.com/FasterXML/jackson/wiki/Jackson-Releases)
8*0ed15c77SAndroid Build Coastguard Workerwiki page
9*0ed15c77SAndroid Build Coastguard Worker
10*0ed15c77SAndroid Build Coastguard Worker## Reporting a Vulnerability
11*0ed15c77SAndroid Build Coastguard Worker
12*0ed15c77SAndroid Build Coastguard WorkerThe recommended mechanism for reporting possible security vulnerabilities follows
13*0ed15c77SAndroid Build Coastguard Workerso-called "Coordinated Disclosure Plan" (see [definition of DCP](https://vuls.cert.org/confluence/display/Wiki/Coordinated+Vulnerability+Disclosure+Guidance)
14*0ed15c77SAndroid Build Coastguard Workerfor general idea). The first step is to file a [Tidelift security contact](https://tidelift.com/security):
15*0ed15c77SAndroid Build Coastguard WorkerTidelift will route all reports via their system to maintainers of relevant package(s), and start the
16*0ed15c77SAndroid Build Coastguard Workerprocess that will evaluate concern and issue possible fixes, send update notices and so on.
17*0ed15c77SAndroid Build Coastguard WorkerNote that you do not need to be a Tidelift subscriber to file a security contact.
18*0ed15c77SAndroid Build Coastguard Worker
19*0ed15c77SAndroid Build Coastguard WorkerAlternatively you may also report possible vulnerabilities to `info` at fasterxml dot com
20*0ed15c77SAndroid Build Coastguard Workermailing address. Note that filing an issue to go with report is fine, but if you do that please
21*0ed15c77SAndroid Build Coastguard WorkerDO NOT include details of security problem in the issue but only in email contact.
22*0ed15c77SAndroid Build Coastguard WorkerThis is important to give us time to provide a patch, if necessary, for the problem.
23