Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Security: FasterXML/jackson-dataformat-xml

Security

SECURITY.md

Last Updated: 2022-09-20

Supported Versions

Current status of open branches, with new releases, can be found fromJackson Releaseswiki page

Reporting a Vulnerability

The recommended mechanism for reporting possible security vulnerabilities followsso-called "Coordinated Disclosure Plan" (seedefinition of DCPfor general idea). The first step is to file aTidelift security contact:Tidelift will route all reports via their system to maintainers of relevant package(s), and start theprocess that will evaluate concern and issue possible fixes, send update notices and so on.Note that you do not need to be a Tidelift subscriber to file a security contact.

Alternatively you may also report possible vulnerabilities toinfo at fasterxml dot commailing address. Note that filing an issue to go with report is fine, but if you do that pleaseDO NOT include details of security problem in the issue but only in email contact.This is important to give us time to provide a patch, if necessary, for the problem.

Verifying Artifact signatures

(for more in-depth explanation, seeApache Release Signing document)

To verify that any given Jackson artifact has been signed with a valid key, have a look atKEYS file of the main Jackson repo:

https://github.com/FasterXML/jackson/blob/master/KEYS

which lists all known valid keys in use.

There aren’t any published security advisories


[8]ページ先頭

©2009-2025 Movatter.jp