Kerentanan dan penanganan insiden¶
Product vulnerability reports¶
Lihat juga
Silakan baca Menggunakan AI untuk membuat isu jika Anda telah menggunakan AI untuk menemukan isu keamanan di Weblate.
Tim pengembang Weblate sangat berkomit untuk melaporkan dan mengungkapkan isu keamanan secara bertanggung jawab. Kami telah mengadopsi dan mengikuti kebijakan yang bertujuan untuk memberikan pembaruan keamanan yang tepat waktu kepada Weblate.
Product vulnerability reports cover security issues in Weblate source code, release artifacts, and documented Weblate security properties. They do not replace operational incident response for a particular deployment.
Reports concerning the separately distributed Weblate Client (wlc) are
evaluated against the wlc threat model, which documents
its intended trust boundaries, supported security properties, and explicit
non-goals.
Kebanyakan kerusakan normal di Weblate dilaporkan ke pelacak isu GitHub publik kami, tetapi karena sifat sensitif dari isu keamanan, kami meminta agar isu tersebut tidak dilaporkan ke publik dengan cara ini.
Sebaliknya, jika Anda yakin telah menemukan sesuatu di Weblate yang memiliki implikasi keamanan, silakan kirimkan deskripsi isu tersebut ke security@weblate.org, GitHub, atau gunakan HackerOne.
Self-hosted operators should use this process when they believe an incident in their own deployment is caused by a Weblate product vulnerability. Local containment, recovery, customer notification, provider escalation, and other deployment-specific incident response remain the operator's responsibility.
A member of the security team will respond to you within 48 hours, and depending on what action is taken, you may get more follow-up emails. Suspected active exploitation and severe security incidents receive immediate internal attention under Incident reporting. Acknowledging a report or completing an investigation does not postpone reporting deadlines.
Catatan
Mengirim laporan terenkripsi
Jika Anda ingin mengirim surel terenkripsi (opsional), silakan gunakan kunci publik untuk security@weblate.org dengan ID 8EA7 6E43 0976 3323 C2E3 D5A0 C472 9F23 8A80 EA93.
Kunci publik ini tersedia di server kunci yang paling umum digunakan, menggunakan WKD atau langsung dari weblate.org.
Petunjuk
Weblate depends on third-party components for many things. In case you find a vulnerability affecting one of those components in general, please report it directly to the respective project. If it also affects a shipped Weblate artifact or a Weblate deployment, report that impact to Weblate through the private channels above.
Beberapa di antaranya adalah:
Lihat juga
Weblate-operated service incidents¶
Operational incidents affecting Hosted Weblate, Dedicated Weblate, or other deployments operated by Weblate s.r.o. are handled using Rencana respons insiden untuk Weblate.
When such an incident also involves a Weblate product vulnerability, the vulnerability report and public advisory follow the product vulnerability reporting process and Kebijakan pengungkapan kerentanan on this page.
Self-hosted deployment incidents¶
Operators of self-hosted Weblate deployments are responsible for their local incident response process, including containment, recovery, notification, and provider-specific escalation. The Weblate-operated Rencana respons insiden untuk Weblate can be used as a reference, but it is not a maintained incident response plan for third-party deployments.
If a self-hosted incident appears to be caused by a Weblate product vulnerability, report it using the product vulnerability reporting process above.
Kebijakan pengungkapan kerentanan¶
Weblate publishes a security advisory alongside a release containing a vulnerability fix at https://github.com/WeblateOrg/weblate/security/advisories. Advisories identify affected versions, impact, severity, and steps users can take to remediate the vulnerability.
Technical details may be delayed when publishing them would create greater security risks than benefits while users apply the fix. The incident handler records the reason and a review date in the private incident note. This does not delay authority reports or protective advice users need.
User notifications¶
Weblate informs impacted users of active exploitation or severe security incidents without undue delay, including available mitigations and corrective actions. Where appropriate, warnings address all users. Known affected contacts, including Hosted and Dedicated Weblate customers, receive e-mail notifications. Public GitHub security advisories provide warnings and updates for self-hosted users whose contact details are not known.
Initial warnings can provide protective advice before a fix or detailed vulnerability disclosure is ready. Authority reporting, user warnings, and publication of technical details proceed separately as needed.
Personal-data breaches also require a separate assessment of notifications to affected individuals, even when there is no active exploitation or severe product-security incident.