Skip to content

Security: bosch-aisecurity-aishield/watchtower

SECURITY.md

Security Policy

🔒 Security is of utmost importance to us. We are committed to ensuring the safety and protection of our users' data and our software products and services. If you have discovered a vulnerability, we appreciate your help in disclosing it to us responsibly.

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

If you believe you’ve found a security vulnerability in our repository, please follow these steps to report it:

  1. Create an Issue: Open an issue in the repository Issue Tracker. Use [BUG] Security Vulnerability as the title but do not include any vulnerability details in the issue description.
  2. Send an Email: Send us an email at AIShield.Contact@bosch.com with the following:
    • The link to the issue you created.
    • Your GitHub handle.
    • Details about the vulnerability, including a description, evidence, and instructions to reproduce the issue.

Communication

  • We prefer all communications to be in English.
  • Please do not disclose any details about the vulnerability publicly.
  • After validating the vulnerability, we will reply to the issue and open a draft security advisory to discuss the details there.

Investigation and Recognition

We will investigate the reported vulnerability and coordinate with you, providing updates on our progress and resolution. Once a fix has been released, we will use the Security Advisory to announce the findings and may recognize you as the finder.

Responsible Disclosure

We aim for timely resolution and disclosure to protect the interests of our users and prevent misuse of the information. During the investigation, if the need arises, we, along with you, may provide early public vulnerability disclosure to protect users.

Thank you for helping us keep our community safe! 🔐

There aren’t any published security advisories