1 Star 0 Fork 23

坐看云起 / NetBox

forked from Gitee 极速下载 / NetBox 
加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
克隆/下载
SECURITY.md 2.16 KB
一键复制 编辑 原始数据 按行查看 历史
jeremystretch 提交于 2023-01-23 10:23 . Reference GitHub advisory reporting

Security Policy

No Warranty

Per the terms of the Apache 2 license, NetBox is offered "as is" and without any guarantee or warranty pertaining to its operation. While every reasonable effort is made by its maintainers to ensure the product remains free of security vulnerabilities, users are ultimately responsible for conducting their own evaluations of each software release.

Recommendations

Administrators are encouraged to adhere to industry best practices concerning the secure operation of software, such as:

  • Do not expose your NetBox installation to the public Internet
  • Do not permit multiple users to share an account
  • Enforce minimum password complexity requirements for local accounts
  • Prohibit access to your database from clients other than the NetBox application
  • Keep your deployment updated to the most recent stable release

Reporting a Suspected Vulnerability

If you believe you've uncovered a security vulnerability and wish to report it confidentially, you may do so via email. Please note that any reported vulnerabilities MUST meet all the following conditions:

  • Affects the most recent stable release of NetBox, or a current beta release
  • Affects a NetBox instance installed and configured per the official documentation
  • Is reproducible following a prescribed set of instructions

Please note that we DO NOT accept reports generated by automated tooling which merely suggest that a file or file(s) may be vulnerable under certain conditions, as these are most often innocuous.

If you believe that you've found a vulnerability which meets all of these conditions, please submit a draft security advisory on GitHub, or email a brief description of the suspected bug and instructions for reproduction to security@netbox.dev. For any security concerns regarding NetBox deployed via Docker, please see the netbox-docker project.

Bug Bounties

As NetBox is provided as free open source software, we do not offer any monetary compensation for vulnerability or bug reports, however your contributions are greatly appreciated.

Python
1
https://gitee.com/sitseecloud/NetBox.git
git@gitee.com:sitseecloud/NetBox.git
sitseecloud
NetBox
NetBox
master

搜索帮助