Skip to content

Commit

Permalink
Add website page about secutity/CVEs
Browse files Browse the repository at this point in the history
  • Loading branch information
jodastephen committed Apr 15, 2024
1 parent 34197d2 commit 8234e04
Show file tree
Hide file tree
Showing 3 changed files with 28 additions and 0 deletions.
1 change: 1 addition & 0 deletions src/site/markdown/index.md
Expand Up @@ -32,6 +32,7 @@ Various documentation is available:
* The [Javadoc](apidocs/index.html)
* The list of [FAQ](faq.html)s.
* The [change notes](changes-report.html) for each release
* The [security](security.html) issues page
* The [GitHub](https://github.com/JodaOrg/joda-time) source repository


Expand Down
26 changes: 26 additions & 0 deletions src/site/markdown/security.md
@@ -0,0 +1,26 @@
## Joda-Time Security

### Security Policy

#### Supported Versions

If a security issue occurs, only the latest version is guaranteed to be patched.

#### Reporting a Vulnerability

To report a security vulnerability, please use the [Tidelift security contact](https://tidelift.com/security).
Tidelift will coordinate the fix and disclosure.


### CVEs

#### CVE-2024-23080

This was raised publicly on 2024-04-10.
There was no prior warning or private disclosure.

The CVE is nonsense. It was raised by an AI-driven bot.
The CVE describes that a `NullPointerException` is thrown when `null` is passed into a method.
As any Java developer knows, this is perfectly normal and not a security issue or CVE.

Users of Joda-Time do not need to take any action as the CVE is invalid.
1 change: 1 addition & 0 deletions src/site/site.xml
Expand Up @@ -130,6 +130,7 @@
<item name="Release notes" href="changes-report.html"/>
<item name="Old release notes" href="installation.html"/>
<item name="Dependency info" href="dependency-info.html"/>
<item name="Security" href="security.html"/>
<item name="Download" href="download.html"/>
</menu>

Expand Down

0 comments on commit 8234e04

Please sign in to comment.