漏洞和事件处理¶
产品漏洞报告¶
参见
如果你已经使用 AI 来发现 Weblate 中的安全问题,请阅读 使用 AI 创建问题。
Weblate 开发团队坚定致力于安全相关问题负责任的报告和披露。我们已经实施并遵守和及时向 Weblate 传输安全更新目标相适应的政策。
Product vulnerability reports cover security issues in Weblate source code, release artifacts, and documented Weblate security properties. They do not replace operational incident response for a particular deployment.
Reports concerning the separately distributed Weblate Client (wlc) are
evaluated against the wlc threat model, which documents
its intended trust boundaries, supported security properties, and explicit
non-goals.
多数 Weblate 中的常规 bug 可以报告到我们的公开 GitHub issues tracker,但由于安全问题的敏感本质,我们请求不要用这种方式公开报告此类问题。
假如您觉得在 Weblate 中发现了某些有安全影响的东西,请将此问题的描述提交到 security@weblate.org、GitHub 或使用 HackerOne 。
Self-hosted operators should use this process when they believe an incident in their own deployment is caused by a Weblate product vulnerability. Local containment, recovery, customer notification, provider escalation, and other deployment-specific incident response remain the operator's responsibility.
A member of the security team will respond to you within 48 hours, and depending on what action is taken, you may get more follow-up emails. Suspected active exploitation and severe security incidents receive immediate internal attention under 事件报告. Acknowledging a report or completing an investigation does not postpone reporting deadlines.
备注
发送加密报告
如果想发送加密邮件(可选),请使用 security@weblate.org 的公钥,ID 为 8EA7 6E43 0976 3323 C2E3 D5A0 C472 9F23 8A80 EA93.
最常用的 key 服务器上有这枚公钥,使用 WKD 或 直接从 weblate.org.
提示
Weblate 在很多事情上依赖于第三方部件。如果你发现一个影响这些部件的漏洞,请直接报告给相应的项目。如果它也影响已发布的 Weblate 工件或 Weblate 部署,请将该影响通过上方的私下渠道将该影响报告给 Weblate。
这些中的一些是:
Weblate 所运营服务的事故¶
Operational incidents affecting Hosted Weblate, Dedicated Weblate, or other deployments operated by Weblate s.r.o. are handled using Weblate 事件响应计划.
When such an incident also involves a Weblate product vulnerability, the vulnerability report and public advisory follow the product vulnerability reporting process and 漏洞披露政策 on this page.
自托管服务部署事故¶
Operators of self-hosted Weblate deployments are responsible for their local incident response process, including containment, recovery, notification, and provider-specific escalation. The Weblate-operated Weblate 事件响应计划 can be used as a reference, but it is not a maintained incident response plan for third-party deployments.
If a self-hosted incident appears to be caused by a Weblate product vulnerability, report it using the product vulnerability reporting process above.
漏洞披露政策¶
Weblate 在 https://github.com/WeblateOrg/weblate/security/advisories 发布安全公告以及包含漏洞修复的版本。公告确认受影响的版本、影响、严重性以及用户可采取的缓解漏洞的步骤。
Technical details may be delayed when publishing them would create greater security risks than benefits while users apply the fix. The incident handler records the reason and a review date in the private incident note. This does not delay authority reports or protective advice users need.
用户通知¶
Weblate informs impacted users of active exploitation or severe security incidents without undue delay, including available mitigations and corrective actions. Where appropriate, warnings address all users. Known affected contacts, including Hosted and Dedicated Weblate customers, receive e-mail notifications. Public GitHub security advisories provide warnings and updates for self-hosted users whose contact details are not known.
Initial warnings can provide protective advice before a fix or detailed vulnerability disclosure is ready. Authority reporting, user warnings, and publication of technical details proceed separately as needed.
Personal-data breaches also require a separate assessment of notifications to affected individuals, even when there is no active exploitation or severe product-security incident.