Eclipse Enclave adheres to the Eclipse Foundation Vulnerability Reporting Policy.
If you believe you have found a vulnerability, report it through coordinated disclosure.
Do not report security vulnerabilities through public issues, discussions, or pull requests.
Instead, use one of these private channels:
- Email the Eclipse Foundation Security Team.
- Create a confidential issue in the Eclipse Foundation Vulnerability Reporting Tracker.
See the Eclipse Foundation Security page for more information about reporting and disclosure.
Include as much of the following information as possible:
- The type and impact of the issue.
- Affected versions, branches, or commits.
- Steps and configuration required to reproduce it.
- The relevant source file locations.
- Related log files, proof-of-concept code, or exploit code when available.
Eclipse Enclave does not currently maintain stable release lines. Security
fixes are applied to the current main branch and published in the latest
rolling prerelease. Older rolling builds are not supported.