Gelhaus Solutions
CNA scope statement
The scope as submitted, what it covers for each product, and what has been asked for but not yet granted. The reporting process is on the policy page.
Statement
Vulnerabilities in the products and services of Gelhaus Solutions that are not in the scope of another CNA. This includes the GHub product line and the tools published under the Gelhaus Solutions organisation.
For each product the scope covers its source repositories, the artifacts released or distributed from them, and the production deployments Gelhaus Solutions operates, whether or not the source is public at the time the vulnerability is reported.
Vulnerabilities in Postiz are not in this scope. Postiz is covered by its own CNA.
That is the statement in full. Everything below is the same thing said in more detail, and if the two ever disagree the statement above is the one that counts.
A product is not just its repository
Scope is stated per product and covers the whole of it: the source repository, whatever is released or distributed from it, and the deployment run by Gelhaus Solutions. A finding in a hosted instance is in scope on the same terms as one in the code, because to the person affected by it there is no difference.
Not all of the GHub repositories are public yet. That makes no difference to scope. A vulnerability in a product is the product's vulnerability whether or not you could read the source when you found it, and a report against a component that has not been published yet is handled on the same terms as any other. Publishing the repositories will add nothing to this page, which is the point.
Where one name covers more than one deployable thing — an app and a runner, a platform and the instance of it — the entry in the list says so rather than leaving it to be inferred.
Anything not listed
Reports about something not on this page still get read and still get an answer. If it turns out to be mine, it gets added here and handled under the policy. If it belongs to somebody else, it gets pointed at them.
Nothing is refused for being unlisted. The list states what is already known to be covered; it is not a filter on the inbox.
In scope
11 products
5 of them have nothing released yet. They are listed because scope should exist before the first release rather than be added after it, and they are marked so nobody goes looking for something to test.
Requested, not in effect
Proposed extension Asked of MITRE. Awaiting a decision.
This is not currently in scope. It is a proposal, and it is deliberately not part of the statement above.
Vulnerabilities in third-party projects onboarded to gadvisory.org whose maintainers request an identifier from Gelhaus Solutions, where the project is not in the scope of another CNA and its maintainers have asked for or agreed to the assignment.
Not in scope
Listed rather than omitted, so the boundary against other CNAs and upstream projects can be checked rather than assumed.
Organisation
Reporting one of these
The channels, the response times and the safe harbour terms are on the policy page. This one only says what is covered.