Skip to content

Security: data-altinn-no/plugin-trad

SECURITY.md

Security

Thanks for helping make data.altinn.no safe for everyone.

The Norwegian Digitalisation Agency (Digdir) takes the security of its software products and services seriously, including all of the open source code repositories managed through the data-altinn-no organisation and the other Digdir organisations on GitHub, such as Altinn, Digdir and Fellesløsninger.

Reporting a vulnerability

If you believe you have found a security vulnerability in any repository in this organisation, or in the data.altinn.no service itself, please report it to us through coordinated disclosure.

Important

Do not report security vulnerabilities through public GitHub issues, discussions or pull requests.

Instead, contact us through the channels described in Digdir's security.txt.

Please include as much of the information listed below as you can. It helps us triage your report more quickly.

  • The type of issue, for example injection, broken access control or information disclosure
  • Which repository, service or environment is affected, for example the API, eBevis, Tilda or the portal
  • The location of the affected source code, as a tag, branch, commit or direct URL
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code, if possible
  • The impact of the issue, including how an attacker might exploit it

Policy

See Digdir's Responsible Disclosure Policy.

There aren't any published security advisories