Security

How we handle vulnerabilities

Gelhaus Solutions is the applicant behind the CNA that covers this work. The policy says what we commit to, the scope says what is covered, and the record shows what has actually been published.

Three documents

What we commit to, what is covered by it, and what has actually been published. The last of those carries live figures with their sources and the date each was checked.

Document What it answers
Disclosure policy How to report something, what happens next, and the timelines Gelhaus Solutions commits to.
CNA scope Which software is covered by the CVE Numbering Authority, and which is deliberately excluded.
The record Every figure this organisation states about its own advisory work, with the source and the time it was last checked.

Reporting a vulnerability in any of this: the channels are on the contact page, and the machine-readable version is at /.well-known/security.txt.

The person behind Gelhaus Solutions also holds a CNA role at Postiz, which is a different organisation and a different programme. That work is described on his own site.