Skip to content

Security: shellui-dev/Avalonia

Security

SECURITY.md

Security Policy

Avalonia is free and open-source software published by AvaloniaUI OÜ. The framework is made publicly available at no charge and is not placed on the market within the meaning of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). AvaloniaUI OÜ acts as the project's open-source software steward and maintains this cybersecurity policy in that capacity, in line with Article 24 of that Regulation.

Reporting a Vulnerability

If you discover a security vulnerability in any of our SDKs, tools, services, or repositories, please help us keep the community safe by reporting it responsibly.

Please avoid disclosing the issue publicly until we have had a reasonable amount of time to investigate and release a patch or mitigation. We review all legitimate reports and will work with you to resolve the issue as quickly as possible.

Reporting via GitHub

We strongly encourage security vulnerabilities to be reported privately through GitHub Security Advisories:

https://github.com/AvaloniaUI/Avalonia/security

To submit a report, visit the security page and click "Report a vulnerability". GitHub will create a private security advisory that allows you and the Avalonia team to collaborate confidentially on the issue until a fix is available.

If you are unfamiliar with GitHub's private vulnerability reporting process, GitHub provides detailed instructions here:

https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability


Reporting via Email

Alternatively, you may report security vulnerabilities by emailing security@avaloniaui.net.

What to Expect

  • We aim to acknowledge your report within 2 business days.
  • We aim to confirm whether we consider it a vulnerability and to share a remediation timeline within 10 business days.
  • We will keep you informed of progress and coordinate the disclosure date with you.
  • We will credit you in the published advisory unless you ask us not to.

These timescales are the targets we work to for the open-source project; they are not contractual commitments. Organisations that require contractually binding response and remediation times can obtain them under a commercial agreement.

Please note that Avalonia does not operate a bug bounty programme.

Versions Receiving Security Fixes

Version Security fixes
11.x and older Not provided
12.x (current stable) Provided

Security fixes are delivered at the head of the current stable series. If a vulnerability affects earlier 12.x releases, we fix it in a new release of the latest version, and the remediation path is to upgrade to that release. Security fixes for the current series are published openly and free of charge. Access to Avalonia's open-source releases, updates and security fixes is never conditional on payment.

Scope

This policy covers the Avalonia framework packages published from this repository (Avalonia and the Avalonia.* platform and integration packages).

There aren't any published security advisories