Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[eclipse.org-committers] Update: Vulnerability Reports no longer accepted by email

Dear all,

We're writing to announce an update to how the Eclipse Foundation Security Team receives and handles vulnerability reports addressed to projects. Effective today, the team will no longer accept vulnerability reports submitted by email. The sections below describe the current process, what’s changing, and any actions you may need to take.

How vulnerability reporting works today

Until now, security researchers could report findings in three ways: through a project's GitHub Private Vulnerability Reporting (for projects who have it enabled), our vulnerability-reports GitLab issue tracker, or by emailing us directly.

What's changing

As of today, we will no longer accept vulnerability reports by email. Any report sent to our security email address on or after this date will not be processed. An auto responder will be created to warn vulnerability reporters about the change. The address itself remains open for all other correspondence.

Going forward, security researchers should report findings either through a project's GitHub Private Vulnerability Reporting or through our dedicated issue tracker: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/new

Using the issue tracker requires an Eclipse account, which can be created here: https://accounts.eclipse.org/user/register/

We're also working to support anonymous reporting and will share more once it's available.

Actions needed

Because the reporting channels have changed, your project's SECURITY.md may now point to options that are no longer valid. We've prepared an updated template reflecting these changes, which can be found here: https://github.com/eclipse-csi/security-handbook/blob/main/templates/SECURITY.md

We kindly ask each project to update its SECURITY.md to list only supported channels.

Why we're making these changes

We've seen a significant increase in the volume of vulnerability reports, including a growing share of automated, AI-generated submissions. Concentrating intake on a single channel lets us triage genuine reports more reliably, improve response times, and ensure legitimate security issues receive the attention they require.

Other questions

For any non-vulnerability inquiry, you can still reach us at our usual address.

Feel free to discuss, comment, or ask questions about this change on the following discussion: https://github.com/orgs/eclipse-csi/discussions/16.

Thank you for helping us keep our projects secure.

Eclipse Foundation Security Team

Back to the top