Leochaileacht agus láimhseáil teagmhas¶
Tuairiscí leochaileachta táirgí¶
See also
Léigh Úsáid AI chun fadhbanna a chruthú le do thoil i gcás gur úsáid tú AI chun fadhb slándála a aimsiú i Weblate.
Tá foireann forbartha Weblate tiomanta go láidir do thuairisciú freagrach agus nochtadh saincheisteanna a bhaineann le slándáil. Ghlacamar le beartais atá dírithe ar nuashonruithe slándála tráthúla a sheachadadh do Weblate agus leanaimid iad.
Clúdaíonn tuarascálacha leochaileachta táirgí saincheisteanna slándála i gcód foinse Weblate, i ndéantúsáin scaoilte, agus i n-airíonna slándála doiciméadaithe Weblate. Ní chuireann siad ionad freagartha teagmhais oibríochtúla le haghaidh imscaradh ar leith.
Reports concerning the separately distributed Weblate Client (wlc) are
evaluated against the wlc threat model, which documents
its intended trust boundaries, supported security properties, and explicit
non-goals.
Tuairiscítear formhór na bhfabhtanna gnáth i Weblate chuig ár rianaitheoir saincheisteanna GitHub poiblí, ach mar gheall ar nádúr íogair saincheisteanna slándála, iarraimid gan iad a thuairisciú go poiblí ar an mbealach seo.
Ina áit sin, má chreideann tú go bhfuil rud éigin aimsithe agat in Weblate a bhfuil impleachtaí slándála aige, seol tuairisc ar an gceist chuig security@weblate.org, GitHub, nó ag baint úsáide as HackerOne.
Ba chóir d’oibreoirí féinóstáilte an próiseas seo a úsáid nuair a chreideann siad gur leochaileacht táirge Weblate is cúis le teagmhas ina n-imscaradh féin. Fanann srianadh áitiúil, téarnamh, fógra do chustaiméirí, ardú céime soláthraithe, agus freagairt eile do theagmhais shonracha maidir le himscaradh de fhreagracht an oibreora.
A member of the security team will respond to you within 48 hours, and depending on what action is taken, you may get more follow-up emails. Suspected active exploitation and severe security incidents receive immediate internal attention under Incident reporting. Acknowledging a report or completing an investigation does not postpone reporting deadlines.
Note
Tuairiscí criptithe á seoladh
Más mian leat ríomhphost criptithe a sheoladh (roghnach), bain úsáid as an eochair phoiblí do security@weblate.org leis an aitheantóir 8EA7 6E43 0976 3323 C2E3 D5A0 C472 9F23 8A80 EA93.
Tá an eochair phoiblí seo ar fáil ar na freastalaithe eochracha is coitianta a úsáidtear, ag baint úsáide as WKD nó go díreach ó weblate.org.
Hint
Weblate depends on third-party components for many things. In case you find a vulnerability affecting one of those components in general, please report it directly to the respective project. If it also affects a shipped Weblate artifact or a Weblate deployment, report that impact to Weblate through the private channels above.
Seo cuid acu:
See also
Teagmhais seirbhíse arna n-oibriú ag Weblate¶
Déileáiltear le teagmhais oibríochtúla a mbíonn tionchar acu ar Weblate Óstáilte, Weblate Tiomnaithe, nó imscaradh eile arna oibriú ag Weblate s.r.o. ag baint úsáide as Plean freagartha teagmhais do Weblate.
Nuair a bhaineann le teagmhas den sórt sin leochaileacht táirge Weblate freisin, leanann an tuarascáil leochaileachta agus an chomhairle phoiblí an próiseas tuairiscithe leochaileachta táirge agus Polasaí nochta leochaileachta ar an leathanach seo.
Teagmhais imscartha féinóstáilte¶
Tá oibreoirí imscaradh féinóstáilte Weblate freagrach as a bpróiseas freagartha teagmhais áitiúil, lena n-áirítear coinneáil, téarnamh, fógra, agus ardú céime atá sainiúil don soláthraí. Is féidir an Plean freagartha teagmhais do Weblate atá á oibriú ag Weblate a úsáid mar thagairt, ach ní plean freagartha teagmhais cothabháilte é le haghaidh imscaradh tríú páirtí.
Más cosúil gur leochaileacht táirge Weblate ba chúis le teagmhas féinóstáilte, tuairiscigh é trí úsáid a bhaint as an bpróiseas tuairiscithe leochaileachta táirge thuas.
Polasaí nochta leochaileachta¶
Weblate publishes a security advisory alongside a release containing a vulnerability fix at https://github.com/WeblateOrg/weblate/security/advisories. Advisories identify affected versions, impact, severity, and steps users can take to remediate the vulnerability.
Technical details may be delayed when publishing them would create greater security risks than benefits while users apply the fix. The incident handler records the reason and a review date in the private incident note. This does not delay authority reports or protective advice users need.
User notifications¶
Weblate informs impacted users of active exploitation or severe security incidents without undue delay, including available mitigations and corrective actions. Where appropriate, warnings address all users. Known affected contacts, including Hosted and Dedicated Weblate customers, receive e-mail notifications. Public GitHub security advisories provide warnings and updates for self-hosted users whose contact details are not known.
Initial warnings can provide protective advice before a fix or detailed vulnerability disclosure is ready. Authority reporting, user warnings, and publication of technical details proceed separately as needed.
Personal-data breaches also require a separate assessment of notifications to affected individuals, even when there is no active exploitation or severe product-security incident.