diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..766e6a9 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,137 @@ +# Security Policy + +At SUSE, we are deeply committed to maintaining the trust of our customers and the broader +open-source community. Open collaboration, transparency, and secure product development are +fundamental to our mission. + +> [!IMPORTANT] +> Please refer to our company-wide +[SUSE Coordinated Vulnerability Disclosure ("CVD") Policy][CVD Policy], for more information. + +We go through all reported security issues, reviewing them with the project's maintainers and +coordinating the fixes and disclosures. We credit all accepted reports from users and security +researchers in our [Security Advisories][advisories]. + +## What SUSE considers a valid vulnerability + +> [!CAUTION] +> Do not test potential exploits or vulnerabilities on any system without explicit authorization +from the system owner. + +### Valid + +> [!WARNING] +> Reported vulnerabilities must affect a supported version of the SUSE Rancher ecosystem. Refer to +[SUSE Support Lifecycle][lifecycle] for current support status. + +Example of valid reports: + +- XSS on Rancher Manager UI. +- Privilege escalation through Rancher Manager RBAC. + +If you are unsure, check the types of issues NOT to report below. + +### Invalid + +Do NOT report the following via this channel: + +- Public CVEs generated by automated scanners (e.g., Trivy, Snyk) as they are fixed as part of the +development process. +- Non-security bugs or documentation improvements. Report them via [issues in Rancher][rancher issue] or +[documentation issues][doc issue] issues. +- Self-inflicted issues requiring degraded security settings, or admin-only exploitation. + +## Reporting Instructions and Mandatory Requirements + +Submit reports via email to [psirt@suse.com](mailto:psirt@suse.com). We recommend OpenPGP encrypted +and signed email, please check the [section](#gpg-key---psirtsusecom) below for more details. + +### What information to provide + +> [!WARNING] +> The information below MUST be provided in order for the report to be timely and effectively +analyzed. + +Reports that miss the required information might be considered AI generated spam or reviewed with a +lower priority. + +- **Product Name & Version**: Affected product and version, or GitHub source code link, if the issue +was observed in the source code. +- **Description**: Complete description of the vulnerability. +- **Impact**: Classification of issue type and potential impact when exploited. +- **Steps to Reproduce** Clear, step-by-step reproduction instructions or proof of concept (POC). + +> [!TIP] +> The more information you provide, the faster we will be able to reproduce the issue and address +your concerns more effectively. + +### GPG Key - `psirt@suse.com` + +To ensure the integrity and confidentiality of our communications, we recommend that individuals +reaching out to the SUSE Product Security team utilize openPGP encryption. Note that while message +contents are protected, the email subject or the names of any attached files will be excluded from +encryption. + +Our official public key is available here: +``` +pub ed25519/0xE0D1EF75DEBDFEE9 2026-09-01 [SC] [expires: 2037-09-01] +Key fingerprint = AB20 5CE3 088C 1F1B CE74 DC99 E0D1 EF75 DEBD FEE9 +uid [ full ] SUSE Product Security Incident Response Team psirt@suse.com +sub cv25519/0xA4B7B686CC4152BD 2026-09-01 [E] [expires: 2037-09-01] +Key fingerprint = B13E 46DE 87EB 81D5 15E1 1909 A4B7 B686 CC41 52BD +``` + +The key is listed below in ASCII encoded form. +```pgp +-----BEGIN PGP PUBLIC KEY BLOCK----- +mDMEapZ8VhYJKwYBBAHaRw8BAQdADoggNgBrXHimYH+7t5WVzBnhQmT8UPUIQQWH +pzLMaB+0PVNVU0UgUHJvZHVjdCBTZWN1cml0eSBJbmNpZGVudCBSZXNwb25zZSBU +ZWFtIDxwc2lydEBzdXNlLmNvbT6ImQQTFgoAQRYhBKsgXOMIjB8bznTcmeDR73Xe +vf7pBQJqlnxWAhsDBQkUsUK6BQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJ +EODR73Xevf7pRkMA/0XDeysUhC66NgiF7AVno+QBkyJso2pkbQQG3su+Oi9hAQCd +yy3iScttdmFKTqQr4N7redFAJ3Esw5vtxVzMHZhpCIkCMwQQAQgAHRYhBFzzxI6z +KP0xgVwUfZLb1rIpR3voBQJqlnyMAAoJEJLb1rIpR3voRUUP/0rHbb/m47zHc834 +G1CPaExiYOrtdckXNDwjno/r+2RppWy6ZxtM8KeLz+414NPxYUPNlyAvXd9pY3lW +sxQkDyJFrIJd0MDXiM8gDPyMuEB9k+yWeofJLcx6LfLvwJnFLwSSHcUWqmPcC6AI +TYVRhY6Gn9sNfJ5DnjQCxahZN55aGff2v0KiSPHrDqE59soLOQH7Vv2xuFVoWIYG +E8FZlzfIsfXJX0mBMrDxXO1+SGzDEdmcgLihhLHCcgmTCizz9S2qGLw3yaeI3NDB +xWafFrW80XGELXn+DdWP/khuU+PGfb0JcfroyR6GGNfAX5BC9O7yePGya+fZB8UD +puf93Q58Exu23KmQ00d0p2ey5t+KSFzmhk4knh6T50qEPm5Z04dwlzbnGwrn9qKS +iZuHn82Xx5B8eQ0nUN9jql1k/tjmeSXrhzfwoGhp4vCbz0AwAAglNo7pEb7j0xHF +C866ZCrQsQxVUcJCSox0HC27YZUvw2fvc57Lb+tkIxGi/AS0/Pe6lRHannqDzpwV +EW4WWIf6wE746M38q779p6PrH8Cu+aVWVCw+ZFNgv7GB/k0NeQUeliZ/xb40wKo4 +zwm6X8emOI/jkQ6fF9JCw7PXf+eFsy1CbB8sKCkFDkew1g9008lWnywxtx79c+Ks +tTMW5IlYQE5wWvLmPG87Sow9wHUSiQIzBBABCAAdFiEEXPPEjrMo/TGBXBR9ktvW +silHe+gFAmqWfLMACgkQktvWsilHe+h1Eg//bHdyPYiJPkKvsHf1guYD/OwEWm32 +1KlfKBKzpM1lZyyHjmNLetnytmypixiRvLuk1R4bTrn+AzwfvaJxqP1O3Ffm6Nub +npjhasBK1ehHL1KbN3ayiuOjjHEubj4ODtZd7QTjSLPNCgapL/N69lHoE6z7Hn+O +MSdy+tZdNKYmQSZdtxsLdzUsnbBItQS2X9Ow1Mwxnj2VHlmJ2WAz+RYh/npFbxc0 +jBDuGg8BIAQRovOym7zP3ubIMlWEbj0uEyNdoFh7qyBp/dC7cqMVykMJHMS2ywNJ +ic20wHZNioRkvRmBIfUS2LSSoSX75y5NWunm9umLZq9bveCCANtRnWA/OrWjM9Dv +bYgn3MUP50ppD8VhWg36jqWjQ4el4J+pZR+NnaqQb5EfFqk6LfHgcbEyBjvwx9EI +AxBTLUEsMCQh65O1tA8flp7EsnPNS5Gq43ceZ/2zqSN+nT6P9USrlvoaY7DycG3H +pW0ivUcILFem3Dv+hpOiu8l4fG34Sc+5iSsMP+3C4FF3b3zaT/OZVcrYz+9Lbel+ +wnttWiXAc1uY6g0BDBWfxqINMHTuqyI28kJpJwohIsAJupWiLBPJirbHxz3sCH1k +iTwKsQ9AQB6QG5kbTyI2XvMAoRS9sLJOIgj1XCQ5iPCnCqCW/5yUZXTLEE1hgDrP +4vNXGiDotSsrg1a4OARqlnxWEgorBgEEAZdVAQUBAQdAIK9oQ08e7coYwqNlcumv +kbxAtYZp/znHfF18qmaClEgDAQgHiH4EGBYKACYWIQSrIFzjCIwfG8503Jng0e91 +3r3+6QUCapZ8VgIbDAUJFLFCugAKCRDg0e913r3+6UnaAQCo9GLby0CgazcDlo91 +X99FhvSAKWmszQg/HXmFACe0IwD/Sv7t62yxGgGebbWdzfPbJOMdqo5ZPq8Yqzal +CNPwEwU= +=qfoM +-----END PGP PUBLIC KEY BLOCK----- +``` + +## SUSE Coordinated Vulnerability Disclosure ("CVD") Policy + +Please refer to our [SUSE Coordinated Vulnerability Disclosure ("CVD") Policy][CVD Policy], for more +information about our commitments and what you can expect after reporting a vulnerability, as +well as how to make an anonymous report and more. + + +[CVD Policy]: https://www.suse.com/support/security/cvd-policy/ +[advisories]: https://github.com/rancher/rancher/security/advisories +[doc issue]: https://github.com/rancher/rancher-docs/issues/new/choose +[rancher issue]: https://github.com/rancher/rancher/issues/new/choose +[lifecycle]: https://www.suse.com/lifecycle/ +