Please do not report security vulnerabilities through public GitHub issues, pull requests, or any other public forum.
Suspected security vulnerabilities in fercc should be reported to Microchip's Product Security Incident Response Team (PSIRT):
Responsible disclosure gives us the opportunity to investigate and address the issue before it is made public.
fercc's Rust dependency tree is tracked via Cargo.lock. A software bill of
materials (SBOM) in SPDX format is published alongside each release and
can be used to cross-reference dependencies against vulnerability databases.
Microchip runs a periodic CI job (see Jenkinsfile_UNGE in this repository)
that generates an SBOM from every build and scans it against public
vulnerability databases using Grype. The
job runs at minimum daily on the main branch.
When a vulnerability is identified the responsible engineering team is notified automatically. Issues are triaged and addressed in prioritised order alongside other engineering work. We cannot guarantee a specific response time or remediation schedule.
If your use of fercc requires stronger security guarantees than the above, we encourage you to:
- Run your own SBOM scan against the published
fercc-sbom.spdx.jsonand/orCargo.lockusing a tool which matches your requirements. - Establish your own alerting and remediation pipeline so you can act on new findings according to your own risk tolerance and timelines.