[Security] Inquiry regarding Responsible Disclosure procedure #6699
Replies: 2 comments 1 reply
-
|
Hello @r0s4ngeles Thank you for the inquiry. I've responded to the email that was sent to info@autoware.org . Feel free to contact us from there. |
Beta Was this translation helpful? Give feedback.
1 reply
-
|
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
xmfcx
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Hello Autoware maintainers,
We are a security research team from the BoB (Best of the Best) program in South Korea. We are currently conducting a project on ROS2 vulnerability analysis.
During our research, we discovered a potential security vulnerability within Autoware. We intend to responsibly disclose this issue to the Autoware Foundation.
Since we could not find a specific SECURITY.md file or a designated security contact, we previously attempted to reach out via email, but we have not yet received a response.
We are planning to present our research findings, including this vulnerability, at ROSCon Korea (January 2026). Therefore, we would like to coordinate the disclosure timeline with you beforehand to ensure appropriate mitigation measures are taken.
Could you please provide the correct contact point (email) or guide us through the preferred procedure for reporting this vulnerability securely?
Thank you.
Beta Was this translation helpful? Give feedback.
All reactions