Gelhaus Solutions

CNA scope statement

The scope as submitted, what it covers for each product, and what has been asked for but not yet granted. The reporting process is on the policy page.

Statement

Vulnerabilities in the products and services of Gelhaus Solutions that are not in the scope of another CNA. This includes the GHub product line and the tools published under the Gelhaus Solutions organisation.

For each product the scope covers its source repositories, the artifacts released or distributed from them, and the production deployments Gelhaus Solutions operates, whether or not the source is public at the time the vulnerability is reported.

Vulnerabilities in Postiz are not in this scope. Postiz is covered by its own CNA.

That is the statement in full. Everything below is the same thing said in more detail, and if the two ever disagree the statement above is the one that counts.

A product is not just its repository

Scope is stated per product and covers the whole of it: the source repository, whatever is released or distributed from it, and the deployment run by Gelhaus Solutions. A finding in a hosted instance is in scope on the same terms as one in the code, because to the person affected by it there is no difference.

Not all of the GHub repositories are public yet. That makes no difference to scope. A vulnerability in a product is the product's vulnerability whether or not you could read the source when you found it, and a report against a component that has not been published yet is handled on the same terms as any other. Publishing the repositories will add nothing to this page, which is the point.

Where one name covers more than one deployable thing — an app and a runner, a platform and the instance of it — the entry in the list says so rather than leaving it to be inferred.

Anything not listed

Reports about something not on this page still get read and still get an answer. If it turns out to be mine, it gets added here and handled under the policy. If it belongs to somebody else, it gets pointed at them.

Nothing is refused for being unlisted. The list states what is already known to be covered; it is not a filter on the inbox.

In scope

11 products

5 of them have nothing released yet. They are listed because scope should exist before the first release rather than be added after it, and they are marked so nobody goes looking for something to test.

This is a fork of discord-tickets/bot, only vulnerabilities applying to our repository are in scope.
Vulnogram Partly
This is a fork of vulnogram/vulnogram, only vulnerabilities applying to our repository are in scope.
Gates pull requests behind a contributor application, as a GitHub App or from inside GitHub Actions.
A security advisory platform that isn't tied to one ecosystem's database.
GAnalytics Not released yet
Analytics where every dataset is a module.
Groups and mailing lists, built to be run.
A management broker that runs inside your own infrastructure.
GPlatform Partly Not released yet
Partially in scope, modules shipped by GPlatform are in scope, the actual platform is not, as it is not shipped to prosumers.
GBoarse Not released yet
A stock market simulation.
DAnalytics Not released yet
Discord analytics, stored by shape.
AetherNet Not released yet
A control plane for a fleet of autonomous agents that happen to live in Minecraft.

Requested, not in effect

Proposed extension Asked of MITRE. Awaiting a decision.

This is not currently in scope. It is a proposal, and it is deliberately not part of the statement above.

Vulnerabilities in third-party projects onboarded to gadvisory.org whose maintainers request an identifier from Gelhaus Solutions, where the project is not in the scope of another CNA and its maintainers have asked for or agreed to the assignment.

Until there is an answer this is not in scope and is deliberately absent from the statement above. A third-party project onboarded to gadvisory.org can have its advisory hosted and published there today — that part needs nobody's permission — but the identifier still has to come from the project's own CNA, or from the CNA of last resort where it has none.

Not in scope

Listed rather than omitted, so the boundary against other CNAs and upstream projects can be checked rather than assumed.

Covered by the Postiz CNA, with MITRE as TL-Root, and by GCVE Numbering Authority 125. I run that programme, but it is a separate authority with a separate scope: report Postiz findings there rather than here.
Part of the Postiz platform and covered by the same CNA, despite living in its own repository. Same programme, same place to report.

Organisation

Organisation
Gelhaus Solutions
Jurisdiction
Germany
Status
Application in progress
Advisory prefix
GSSA-

Reporting one of these

The channels, the response times and the safe harbour terms are on the policy page. This one only says what is covered.