Zum Hauptinhalt springen

Security Advisories

ONE WARE publishes an advisory when a security issue in one of our products requires you to act — typically by updating, or by changing a configuration.

Where advisories are published

ProductAdvisory source
ONE WARE Studiogithub.com/one-ware/OneWare/security/advisories
OneWare.AI extensionRelease notes, in-product notification, and direct notice to affected customers
OneWare Self-Hosted WorkerDirect notice to deployment contacts, and release notes for the worker image
Hosted ONE WARE CloudService status and direct notice to affected accounts

Advisories for issues discovered in third-party components are published only where the component is part of a ONE WARE product and the issue affects you in practice. We do not republish upstream advisories that do not.

How to receive notifications

Choose at least one. Do not rely on periodically checking this page — urgent notices are pushed, not posted.

1. Watch the ONE WARE Studio repository. On github.com/one-ware/OneWare, select Watch → Custom → Security alerts. This covers the open-source desktop application.

2. Register a security contact. For commercial products — the OneWare.AI extension, the Self-Hosted Worker and the hosted Cloud — send a monitored contact address to security@one-ware.com with the subject Security contact registration, stating:

  • your organisation,
  • the products and versions you run,
  • a monitored email address (a shared team mailbox is better than an individual).

We use this list to notify you directly for High and Critical issues. This is the only channel that reaches you reliably for the self-hosted worker, because we have no telemetry that tells us who is running it.

3. Keep your deployed versions recorded. An advisory names affected versions. If you do not know what you are running, you cannot tell whether it applies to you.

What an advisory contains

Each advisory states:

  • affected products and version ranges,
  • a description of the issue and its impact,
  • severity, with a CVSS score where one applies,
  • the fixed version, or a mitigation if no fix is available yet,
  • the action you need to take, and by when,
  • a CVE identifier where one has been assigned.

Response expectations

Our targets for handling a report are on the Product Security page. Once a fix is available:

SeverityOur target to publish and ship a fixSuggested target for you to deploy
CriticalAs soon as a tested fix existsWithin 72 hours
HighPromptly, prioritised over feature workWithin 7 days
MediumIn the next scheduled releaseWith your normal update cycle
LowIn a future releaseWith your normal update cycle

Where a fix cannot be delivered quickly, we publish a mitigation first and the fix when it is ready, rather than staying silent.

Coordinated disclosure

We follow coordinated vulnerability disclosure. We publish an advisory once a fix or a workable mitigation is available, and we credit reporters who ask for acknowledgement.

If a vulnerability is being actively exploited, we may publish earlier — the priority is giving you the information you need to protect yourself, even if that is only a mitigation.

Reporting a vulnerability

See Product Security, or email security@one-ware.com with the subject Security. Please do not report vulnerabilities through public issues, Discord, or general support channels.