Mautic Adopts GitHub’s Private Security Reporting System for Vulnerability Reporting

At Mautic, we are dedicated to ensuring the security of our software ecosystem and enhancing the experience of our developers and users. The diligent attention of community members and security researchers has significantly contributed to our ongoing commitment to create safer, more robust software. 

The announcement by huntr – our trusted partner in managing the reporting and communication around software vulnerabilities – that they will shift their strategic focus to only handle vulnerabilities related to AI and ML libraries and frameworks rather than all open source projects, necessitates a transition on our part too. 

We want to ensure that we continue to maintain transparency and open channels of communication with our community on security issues.

With this in mind, we are happy to announce that we are moving to GitHub’s built-in private vulnerability reporting system.

What does this mean for you?

If you have previously reported vulnerabilities or contributed to Mautic using huntr, you can now seamlessly navigate to the Security tab on our GitHub repository page and use the built-in form there to privately report any potential security vulnerability you discover. 

While only the title and description are mandatory on this form, we encourage you to provide as much information as possible to aid our prompt and adequate response. Please check our guidelines on our website for how to write a great report.

Our Commitment

While we transition between these systems, we continue to be committed to the safety of our users and the integrity of our ecosystem. We assure our community that your alerts, concerns, and reports will be attended to with the due diligence and priority they deserve.

We will be communicating with the authors of all open reports as we transition systems and will be including several fixes in upcoming releases.

For a step-by-step guide on how to report a vulnerability using GitHub’s built-in security tab, we recommend referring to the official GitHub reporting guidelines.

We appreciate the efforts of all our community members, and we value your continued contribution and support as we work together in building a safer and more secure Mautic community.

The Mautic Security Team

Share this blog article:
Picture of mauticsecurity

mauticsecurity

More 📝's in

Yellow background with mautic logo top left, Mautic 7.0 columba edition written in text, features bullet pointed: A glimpse at new features: Import and export campaigns Organize your marketing resources with projects Smarter segment-based email sending Multilingual support for SMS and notifications Improved workflows for scheduling emails API v2 based on API Platform, and also an explanation of the constellation shown: Columba is a southern constellation representing a dove in flight. Though less prominent than its northern neighbors, Columba contains the globular cluster NGC 1851, a dense collection of ancient stars visible through telescopes. Named in the 16th century by Dutch astronomer Petrus Plancius, Columba represents the dove from Noah's Ark that returned bearing an olive branch, symbolizing hope and peace after the great flood. In its celestial position south of Orion and Lepus (the Hare), some interpretations suggest the dove fleeing from the hunter. The constellation embodies themes of peace, renewal, and divine guidance across various traditions, serving as a quieter but meaningful counterpart to the more dramatic figures of the night sky.
Product news

Mautic 7: Columba Edition is released

Today we’ve released Mautic 7.0: Columba Edition. It’s here.

This is a full term release with a four-year support cycle – one year active, one year security, two years Extended Long Term Support. Read more about our release strategy.

Search

Use the search bar above by typing terms and pressing enter.