Skip to content

Security: renovatebot/renovate

SECURITY.md

Security / Disclosure

If you find any bug with Renovate that may be a security problem, please report it through the GitHub Security Advisories process. This way we can evaluate the bug and hopefully fix it before it gets abused. Please give us enough time to investigate the bug before you report it anywhere else.

If you would like to discuss a potential finding before raising the Advisory, then e-mail us at: renovate-disclosure@mend.io.

Caution

Review the Mend Developer Platform Terms of Service before attempting to reproduce any issues with the Mend Renovate CLI on Mend-hosted infrastructure.

You may not legally be allowed to reproduce the security issue without advance, express written consent.

Please do not create GitHub issues for security-related doubts or problems.

Publishing

GitHub Security Advisories (GHSAs) will be made public roughly one month after the patch is introduced to Renovate.

This allows time for Mend customers to apply the patch, as well as ensuring that users across the Renovate ecosystem have also been able to receive the patch.

If there is a timeline you are working towards for intended publishing, please let us know ahead of time, so we can determine if this would line up with our own timelines.

Will we request a CVE ID?

It is uncommon for the Renovate project to request a CVE ID.

GHSA IDs are more than sufficient for the ecosystem's ability to reason about security advisories, and requesting a CVE ID on top of this generally doesn't add any additional benefit.

Whether we request a CVE ID is at our discretion. There is no need to ask for us to request one - we will if we feel we need one.

Learn more about advisories related to renovatebot/renovate in the GitHub Advisory Database