Skip to content

Security: jerzyjamroz/epics-base

Security

SECURITY.md

Security Policy

Supported Versions

Security updates and patches are typically applied to the latest active release series of EPICS Base. Older, end-of-life release series do not receive security backports unless specifically maintained by community contributions.

Version Supported
7.0.x ✅
3.15.x ✅
< 3.15 ❌

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or by using EPICS mailing lists.

If you discover a security vulnerability within EPICS Base, please report it privately first, so that it can be addressed responsibly before public disclosure:

  • Primary Method: Please file a Private Security report or issue via the project's tracking systems or reach out directly to the EPICS Core developers via the EPICS Security email address or core development contacts.
  • Details to Include:
    • A description of the vulnerability and its potential impact.
    • Step-by-step instructions or proof-of-concept code to reproduce the issue.
    • The specific version(s) of EPICS Base affected.
  • AI-Generated Reports:
    • Please double-check findings for hallucinations before reporting them.
    • With the wide availability of AI-based tools, we will treat many of those reports as public bugs. However, we still prefer the first report to be private.

You can expect an acknowledgment of your report, followed by coordination on a timeline for investigation and public patching.

There aren't any published security advisories