Scope

The following describes how and when Y2 ENGINEERING SP ZO.O. (a provider of downloadable and cloud-based applications under the Release Management brand name through the Atlassian Marketplace) resolve security bugs in our Apps. It does not describe the complete disclosure or advisory process that we follow.

Security bug fix Service Level Objectives (SLO)

We have defined the following timeframes for fixing security issues in our products:

Accelerated resolution timeframes

These timeframes apply to all cloud-based Release Management LLC Apps, and any other software or system that is managed by Release Management LLC, or is running on Release Management LLC infrastructure.

Extended resolution timeframes

These timeframes apply to all self-managed Release Management LLC products.


Critical vulnerabilities

When a Critical security vulnerability is discovered by Release Management LLC or reported by a third party, Release Management LLC will do all of the following:

Non-critical vulnerabilities

When a security issue of a High, Medium or Low severity is discovered we will include a fix in the next scheduled release.

Other information

Severity level of vulnerabilities is calculated based on Severity Levels for Security Issues by Atlassian.