Security Policy
Reporting Vulnerabilities
Please report security vulnerabilities through the official Jenkins vulnerability reporting process.
- Do not create public issues for security vulnerabilities
- Security reports are handled by the Jenkins Security Team
- You should receive a response within 48 hours
- Expect updates on the vulnerability status throughout the process
Security Updates
All security releases will be announced on: