The OCaml Security Advisory Database is a repository of security advisories filed against the OCaml compiler and OCaml packages published via opam.
It is maintained by the OCaml security team.
On the public mailing list ocsf-ocaml-security-announcements every security advisory will be published. Everyone can subscribe to that mailing list. It is only for security advisories, there won't be any discussion on the mailing list.
In order to quickly process reports, it is great if you can supply:
- A brief description of the vulnerability,
- Indication whether you want to stay anonymous or revealing your name (for the upstream authors and advisory),
- A reproducible example using opam-installed binaries or equivalent,
- A CWE identifier,
- A classification CVSS,
- Indication whether you already requested a CVE number, or want us to do this.
- Please indicate what tooling has been used for finding the issue, including code review, static analysis, or LLM. Both for the reported issue and the report itself.
- Someone (the reporter) reports a security issue to security@ocaml.org or as a private GitHub issue in ocaml/security-advisories repository.
- The OCaml security team replies with "we have received your mail, we'll be back within a week" within three working days; "do you want your identity being disclosed to the upstream author and/or general public?"
- The OCaml security team figures out who (the responder) wants to take the issue within the security team.
- The responder looks at the issue, and if it is valid, it contacts the upstream maintainer(s) of the package, and/or the opam maintainer(s) or author(s) as appropriate (the maintainer(s))
- (4a.) The responder applies for a CVE number unless the reporter already has one.
- (4b.) The responder figures out (with upstream authors) which versions are affected.
- The reporter, responder, and maintainer discuss about the embargo — the usual period is 90 days (but publishing it earlier if there's a patch available is fine)
- When the patch is available, discussion between reporter, maintainer(s), and responder whether this fixes the issue (the reporter may have some test environment and can confirm it).
- Potentially a pre-announcement about which package and when the advisory and patch will be published for core opam packages and high impact vulnerabilities.
- The responder publishes the security advisory
- (8b.) The advisory is sent to the mailing list for security announcements
- (8c.) The maintainer(s) (or the responder) publishes the fixed opam package to opam.ocaml.org (and mark vulnerable packages unavailable)
- (8d.) The responder publishes the security announcement also on the database, which is an input source for OSV