Introduction

This policy defines Sourcegraph's process for incoming security vulnerabilities. It defines roles, responsibilities, steps and SLAs.

Scope

This document concerns how we handle incoming vulnerabilities and engage with Engineering teams to ensure they are fixed. It does not cover tooling and processes to find vulnerabilities. More information on how we execute this process can be found in our . The policy document is the source of truth in case there are any discrepancies between the two documents. If you find conflicting information please raise it to the attention of the Security team.

Vulnerability management stages

  1. Discovery: a vulnerability from any source becomes an item to be triaged by the Security team.
  2. Triaging: Security triages the vulnerability. If confirmed, they write a technical report and engage the code owner.
  3. Engineering estimation: the code owner suggests a patch and provides an estimate of the effort to complete it within the SLA defined by the severity level assigned during the triage process.
  4. Remediation: the code owner patches the issue. Security verifies the patch.
  5. Disclosure: Security discloses the vulnerability according to our vulnerability disclosure process.

Responsibilities

The Security team is responsible for:

Code or system owners are responsible for: