Post a reply

Before posting, please read how to report bug or request support effectively.

Bug reports without an attached log file are usually useless.

Options
Add an Attachment

If you do not want to add an Attachment to your Post, please leave the Fields blank.

(maximum 10 MB; please compress large files; only common media, archive, text and programming file formats are allowed)

Options

Topic review

martin

Re: Support query

We do not have any formal procedure, if that's what you ask for.
We are doing the best we can.
AmirunAN

Re: Support query

Hi Martin,
My colleague and I logged this call twice as we could not see Sid's original post, hence I created an account and logged a second post.

Your response below only answers our third query, we still require response on queries 1 and 2.
Our questions:
Can you confirm how the WinSCP application is updated?

  1. Is it community driven updates?
  2. Is there a security vetting process to ensure vulnerabilities/backdoors are not introduced?
  3. If a security related issue has been identified which is deemed a critical risk, what are the timescales (estimated) for resolving these type of issues? (Martin response: 'Critical issues are typically addressed within several days.')
martin

Re: Support query

Critical issues are typically addressed within several days.
Sid.Naziri

Support query

Hi Support Team

I would like to get confirmation on how the WinSCP application is updated?

  • is it community driven updates?
  • is there a security vetting process to ensure vulnerabilities/backdoors are not introduced?
  • If a security related issue has been identified which is deemed a critical risk, what are the timescales (estimated) for resolving these type of issues?