Pudu programming language
Menu
Package

@chrismichaelps / pudu-lang-log

Structured event logging for Pudu: message templates, enrichment, filtering, formatting, and sinks

0.1.0Apache-2.01

InstallClose

SECURITY.md

Markdown42 lines1.8 KB

GitHub ↗

Security policy

Reporting a vulnerability

Report a suspected vulnerability privately through GitHub's security advisory form, or by email to <chrisperezsantiago1@gmail.com> with SECURITY in the subject.

Please do not open a public issue for a vulnerability. Include the package version, the pudu version, the platform, and the smallest program that shows the problem.

You can expect an acknowledgement within seven days and a decision on whether the report is accepted within thirty.

What is in scope

A logger receives values from the program that uses it, and those values often come from untrusted input. A report is in scope when the package does more with them than its configuration allows:

  • A formatter writing output that breaks its own format: an unescaped quote or control character in JSON, or a line break that forges a second event in a line-oriented text sink.
  • A message template, filter expression, or settings document that crashes the program, loops without end, or grows memory without a bound.
  • A queue or buffer growing past its configured limit, or a file sink writing past its size limit or keeping more files than its retention allows.
  • A file sink writing outside the directory its path names.
  • A logging failure escaping to the caller from a sink that is not an audit sink.

What is not in scope

  • Values the program chooses to log. The package records what it is given; keeping secrets out of events is the caller's decision, helped by destructuring policies and filters.
  • Vulnerabilities in the Pudu compiler or standard library; report those to pudu-lang.

Supported versions

VersionSupported
0.1.xYes