From eb5b3f047cdbb719a07f06671b96cb4f737d852a Mon Sep 17 00:00:00 2001 From: Pierre-Charles David Date: Sun, 2 Aug 2026 10:55:32 +0200 Subject: [PATCH 1/2] [doc] Update SECURITY.md Signed-off-by: Pierre-Charles David --- SECURITY.md | 36 +++++++++++++++++++----------------- 1 file changed, 19 insertions(+), 17 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index d0a8b6d..07a155f 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,25 +1,27 @@ - +# Security Policy -# How To Report a Vulnerability +This Eclipse Foundation Project adheres to the [Eclipse Foundation Vulnerability Reporting Policy](https://www.eclipse.org/security/policy/). -If you think you have found a vulnerability in EMF Validation you can report it using one of the following ways: +## How To Report a Vulnerability -* Contact the [Eclipse Foundation Security Team](mailto:security@eclipse-foundation.org) -* Create a [confidential issue](https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/new?issuable_template=new_vulnerability) +If you think you have found a vulnerability in this repository, please report it to us through coordinated disclosure. -You can find more information about reporting and disclosure at the [Eclipse Foundation Security page](https://www.eclipse.org/security/). +**Please do not report security vulnerabilities through public issues, discussions, or pull requests.** -# Supported Versions +Instead, report it using one of the following ways by creating a [confidential issue](https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/new?issuable_template=new_vulnerability) in the Eclipse Foundation Vulnerability Reporting Tracker - -Supported versions are: -Check individual repositories for latest versions. +You can find more information about reporting and disclosure at the [Eclipse Foundation Security page](https://www.eclipse.org/security/). -# Security Policy +Please include as much of the information listed below as you can to help us better understand and resolve the issue: + +- The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting) +- Affected version(s) +- Impact of the issue, including how an attacker might exploit the issue +- Step-by-step instructions to reproduce the issue +- The location of the affected source code (tag/branch/commit or direct URL) +- Full paths of source file(s) related to the manifestation of the issue +- Configuration required to reproduce the issue +- Log files that are related to this issue (if possible) +- Proof-of-concept or exploit code (if possible) -This project follows [Eclipse Foundation Vulnerability Reporting Policy](https://www.eclipse.org/security/policy/). +This information will help us triage your report more quickly. From b53353e9235ee9a919a41cabc42a1d630bfc01f3 Mon Sep 17 00:00:00 2001 From: Pierre-Charles David Date: Sun, 2 Aug 2026 10:56:39 +0200 Subject: [PATCH 2/2] [releng] Update workflows Signed-off-by: Pierre-Charles David --- .github/workflows/build.yml | 4 ++-- .github/workflows/generate-sbom.yml | 6 +++--- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 099cb2a..bf85af6 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -17,9 +17,9 @@ jobs: runs-on: ${{ matrix.os }} name: OS ${{ matrix.os }} Target ${{ matrix.target }} Java ${{ matrix.java }} build and verify steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Java ${{ matrix.java }} - uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0 + uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 with: distribution: 'temurin' java-version: ${{ matrix.java }} diff --git a/.github/workflows/generate-sbom.yml b/.github/workflows/generate-sbom.yml index e4df72e..c5fad6c 100644 --- a/.github/workflows/generate-sbom.yml +++ b/.github/workflows/generate-sbom.yml @@ -11,9 +11,9 @@ jobs: project-version: ${{ steps.build.outputs.PROJECT_VERSION }} steps: - name: Checkout - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Java - uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0 + uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0 with: distribution: 'temurin' java-version: 17 @@ -22,7 +22,7 @@ jobs: id: build run: | ./mvnw -B -ntp clean package - VERSION=$(./mvnw -q -Dexec.executable="echo" -Dexec.args='${project.version}' --non-recursive org.codehaus.mojo:exec-maven-plugin:3.1.0:exec) + VERSION=$(./mvnw -q help:evaluate -Dexpression=project.version -DforceStdout 2> /dev/null | sed -e 's/-SNAPSHOT//') echo "PROJECT_VERSION=$VERSION" >> $GITHUB_OUTPUT mv releng/org.eclipse.emf.validation.repository/target/bom.json emf-validation-bom.json - name: Upload sbom