Please report security vulnerabilities to security@entropy-data.com.
Do not open a public issue for a security vulnerability.
Helpful details to include:
- affected version or container image tag
- a description of the issue and its impact
- steps to reproduce, or a proof of concept
- any known mitigation
- We acknowledge your report within 3 working days.
- We assess the report and tell you whether we consider it a vulnerability, along with our severity assessment.
- Depending on risk and applicability, we act immediately or plan a fixed version within 30 days, as described in our vulnerability handling policy.
- We keep you updated on progress and let you know when a fix ships.
We ask that you give us reasonable time to release a fix before disclosing the issue publicly, and we are happy to credit you in the advisory unless you prefer otherwise.
This policy covers the Entropy Data product, including the self-hosted container images (entropydata/entropy-data, entropydata/entropy-data-ce) and the deployment templates in this repository.
Reports about our hosted SaaS environment or our corporate systems are welcome at the same address.
- Vulnerability handling — how we monitor and remediate CVEs
- SBOM — a Software Bill of Materials is attached to every container image