Skip to content

Security: rhythmictech/ansible-role-java

Security

SECURITY.md

Security Policy

Rhythmic Technologies takes security seriously. We hold ourselves to high standards for the security of our open source projects.

Supported Versions

We provide security updates for the latest major version of each module. Older major versions may receive critical fixes at our discretion.

Version Supported
Latest Yes
< Latest major Best effort

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report vulnerabilities by emailing security@rhythmictech.com with:

  • A description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any potential mitigations you have identified

Disclosure Timeline

  • Acknowledgment: We will acknowledge receipt within 2 business days.
  • Assessment: We will provide an initial assessment within 7 business days.
  • Fix: We aim to release a fix within 30 days for critical issues.
  • Disclosure: We follow a 90-day coordinated disclosure timeline. We will work with you on timing if the fix requires more time.

Scope

This policy applies to all repositories under the rhythmictech GitHub organization.

Recognition

We appreciate the efforts of security researchers and will acknowledge contributors in release notes (with permission).

There aren’t any published security advisories