Skip to content

Security: ElloTechnology/signoz

Security

SECURITY.md

Security Policy

SigNoz is looking forward to working with security researchers across the world to keep SigNoz and our users safe. If you have found an issue in our systems/applications, please report it to us privately.

Supported Versions

We always recommend using the latest version of SigNoz to ensure you get all security updates.

Reporting a Vulnerability

If you believe you have found a security vulnerability within SigNoz, please let us know right away. We'll try and fix the problem as soon as possible.

Do not report vulnerabilities using public GitHub issues, discussions, or pull requests.

Instead, report it privately through GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click Report a vulnerability, or use this link.
  3. Describe the issue with as much detail as you can — affected version, impact, and steps to reproduce help us triage faster. Please submit one report per vulnerability.

This opens a private advisory visible only to you and the SigNoz maintainers. We'll respond there, keep you updated as we work on a fix, and coordinate disclosure. If the report is valid we'll credit you on the published advisory and request a CVE.

If you're unable to use GitHub's private reporting, you can email security@signoz.io instead.

Thanks

Thank you for keeping SigNoz and our users safe. 🙇

There aren't any published security advisories