Please see the readme.
All security issues must be reported via:
- GitHub private vulnerability issues (preferred), or,
- Email to the private mailing list flatpak-security@lists.freedesktop.org (alternative). You can request to join the list here. Emails should be forwarded to GitHub private security issues by the list maintainers.
Once a security issue is reported, the reporter(s) and the maintainer(s) will work together to determine the validity, scope and severity; confirm the report; audit the codebase for similar issues and prepare a fix for all supported branches.
Once a fix is ready, the maintainer(s) may ask for a CVE to be assigned (usually through GitHub as the CNA) for noteworthy vulnerabilities. Otherwise a GHSA ID will be used for tracking. Please do not request CVE IDs bypassing this process.
Thereafter, the maintainer(s) shall coordinate the public disclosure and the relevant release(s) fixing the issue(s) with the parties involved. This involves sending an email to flatpak-security@lists.freedesktop.org coordinating the release(s).
Reports must remain confidential throughout this process and until the fix has been committed publicly.
There is no strict time limit but generally issues are fixed within 2-3 months of a report but the maintainer(s) can ask for more time on a case-by-case basis.
In case no one has responded to or acknowledged a security issue report, the reporter(s) can choose to make a report public once 90 days have elapsed since the report was submitted.
There shall be no exceptions to this process and the maintainer(s) decision is final.