Skip to content

Update SECURITY.md #15

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 10 additions & 7 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,20 +1,23 @@
<!--
SPDX-FileCopyrightText: 2025 Industria de Diseño Textil S.A. INDITEX

SPDX-License-Identifier: CC-BY-SA-4.0
-->

# Security

We at Inditex believe that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all opensource community.

If you believe you have found a security vulnerability in any Inditex repository that meets Inditex definition of a security vulnerability, please report it to us as described below. We appreciate the hard work maintainers put into fixing vulnerabilities and understand that sometimes more time is required to properly address an issue.

## Reporting Security issues
## Reporting security issues

> IMPORTANT: Do not file public issues on GitHub for security vulnerabilities
> [!CAUTION]
> Do not file public issues on GitHub for security vulnerabilities

* Let us know by submitting the finding through our [disclosure submission program](https://inditex.responsibledisclosure.com/) as soon as possible, upon discovery of a potential security issue.
* Let us know by submitting the finding through our [dedicated email address](mailto:vuln.disclosure@inditex.com) as soon as possible, upon discovery of a potential security issue.
* Once we've assessed your report, we will create a GitHub "security advisory", which will allow the reporter and Inditex team to work on the issue in a confidential manner. We will invite you as a collaborator to the advisory and any needed trusted persons.
* That "security advisory" will also allow us to have a temporary private fork, to work on the fix in confidentiality.
* Once a fix is ready, we will include the fix in our next release and mark that release as a security release.
* Details on the issue will be embargoed for 30 days to give users an oppurtunity to upgrade, after which we will coordinate disclosure with the researcher(s).
* If you've contributed the fix, you will be credited for it.

## Policy

Find out more about our [responsible disclosure policy](https://inditex.responsibledisclosure.com/hc/en-us#vdp_policy)