SECURITY_PROCESS.md
<< Use this section to detail the report received, initial assessment, and validation results >>
Example:
I've reviewed the security report and confirmed this vulnerability exists in Stalwart version X.Y.Z.
Assessment of exploitability:
Potential impact:
Critical|High|Medium|LowX.XX.Y.Z to X.Y.Zcommit-hash or vX.Y.ZNetwork|Local|PhysicalX days/weeks<< Document immediate actions taken and mitigation strategies >>
Example:
Working on hotfix for version X.Y.Z. Temporary workaround available by disabling [feature] in configuration.
Yes|No - If yes, describe brieflyYYYY-MM-DDvX.Y.ZGHSA-XXXX-XXXX-XXXX<< Analysis of potential impact on the Stalwart deployments >>
Based on telemetry data and version statistics, approximately X installations may be affected.
Document your impact assessment process and findings
~X out of YYes|NoFound|Not found|UnknownEmail content|Credentials|Configuration|NoneHigh|Medium|Low<< Communication strategy and release timeline >>
Security release vX.Y.Z will be published on YYYY-MM-DD with coordinated disclosure.
Pre-release preparation:
Communication channels:
Release execution:
Post-release:
YYYY-MM-DD HH:MM UTCGHSA-XXXX-XXXX-XXXXCVE-YYYY-XXXXXX days/weeks