mirror of
git://code.qt.io/qt/qt5.git
synced 2026-10-12 01:57:30 +08:00
Pick-to: 6.12 Change-Id: Ic3e8d43709d1254277810c9e1072240126a26583 Reviewed-by: Gabriel Byman <[email protected]> Reviewed-by: Alexei Cazacov <[email protected]>
1.8 KiB
1.8 KiB
Security policy
Reporting a vulnerability
Report suspected security vulnerabilities in Qt by email to [email protected]. Do not report them in the public bug tracker at bugreports.qt.io.
If you hold a commercial license, you can instead report the issue to the Qt Company support team through the support portal, using the "Security Issues" category.
The policy
QUIP 15 is the Qt Project Security Policy. It is the authoritative source for how the project handles security issues, and it covers:
- How reports are received, acknowledged, and triaged, and in what time frame.
- Who is responsible for addressing an issue, and how it is escalated.
- How issues are disclosed, including CVE handling and notification of packagers.
- Which versions of Qt fixes are guaranteed for.
Security announcements are published to the announce mailing list.
Qt customers with a commercial license now have the opportunity to subscribe to the Qt Early Warning List in the Customer Portal. The EWL subscription requires an active Commercial Qt license.
Related material
- Security in Qt — what Qt does and does not protect against, and how to use Qt securely.
- QUIP 23 — the
Qt-Securityheader that marks how security-relevant a source file is. - QUIP 16 — the branch policy, which governs which branches accept which changes.
- Coordinated Vulnerability Disclosure Policy - Terms and Conditions of Coordinated Vulnerability Disclosure Policy at Qt Group.