Skip to content

Security: log2timeline/plaso

Security

SECURITY.md

Security Policy

This project does not consider minor code weaknesses, vulnerabilities. Minor code weaknesses can be reported as regular issues.

Reporting an actual vulnerability

Please do not open public GitHub issues for security vulnerabilities.

If you discover an actual security vulnerability within this project, please report it privately to the maintainers. This allows us to coordinate a fix and protect users before the flaw is made public.

A finding by a fuzzer or other type of security tool is not necessarily a security vulnerability. Make sure to include an analysis of what makes the finding an actual vulnerability.

How to Report

You can report vulnerabilities through one of the following methods:

  1. Email: Send a detailed report to log2timeline-maintainers at googlegroups.com

What to Include

Please include:

  • A description of the vulnerability and its impact. Do not speculate about impact, and make sure to include your impact analysis. No need to include CVSS scores.
  • Step-by-step instructions to reproduce the issue, including any specific test data or configurations.
    • Report in text, no screenshots or videos.
    • Make sure to include a working proof-of-concept (POC).
    • Add integrity hashes of the files.
  • Any proposed fixes, patches, or mitigations.

There aren't any published security advisories