Skip to content

Security: quickwit-oss/quickwit

SECURITY.md

Security Policy

Vulnerability Reporting

We deeply appreciate any effort to discover and disclose security vulnerabilities responsibly.

Quickwit CI

If you would like to report a vulnerability in Quickwit's CI or have security concerns with other Datadog products, please email security@datadoghq.com.

We take all disclosures seriously and will do our best to respond promptly, verify the vulnerability, and take the necessary steps to fix it. After our initial reply, we will periodically update you on the status of the fix.

Other Reports

Quickwit is an open source project designed to be self-hosted, so users are responsible for managing their deployments. Vulnerabilities in Quickwit deployments could potentially be exploited by malicious actors who already have access to the user's infrastructure. We encourage responsible disclosure by opening a GitHub issue so that risks can be properly assessed and mitigated.

To help us investigate your report, please include any of the following:

  • A proof of concept
  • Any tools used, including their versions
  • Any relevant output

Do not include credentials, secrets, or other sensitive information in a public GitHub issue.

There aren't any published security advisories