Incident response
기준일: 2026-07-26
공식 기준: Incident response
Incident response 문서는 OpenClaw 공식 문서(security/incident-response)를 한국어로 정리한 가이드입니다. How OpenClaw triages, responds to, and follows up on security incidents 명령·설정 키·코드 예시는 공식 문서를 그대로 보존하며, 해석과 절차 안내는 한국어로 제공합니다. 최종 동작은 설치된 CLI 버전과 공식 원문을 확인하세요.
핵심 요약
How OpenClaw triages, responds to, and follows up on security incidents
한국어 가이드 범위: security/incident-response 경로의 설정·명령·제약·예시를 학습용으로 재구성합니다.
문서 구성
공식 문서의 주요 섹션은 다음과 같습니다.
- 1. Detection and triage
- 2. Severity
- 3. Response
- 4. Communication and disclosure
- 5. Recovery and follow-up
- 관련 문서
상세 내용
1. Detection and triage
- Confirm affected component, version, and trust boundary impact. 2. Classify as a security issue vs. hardening/no-action, using
SECURITY.md's scope and out-of-scope rules. 3. An incident owner responds accordingly.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
주요 항목:
- GitHub Security Advisories (GHSA) and private vulnerability reports.
- Public GitHub issues/discussions when reports are not sensitive.
- Automated signals: Dependabot, CodeQL, npm advisories, secret scanning.
2. Severity
| Severity | Definition |
|---|---|
| Critical | Package/release/repository compromise, active exploitation, or unauthenticated trust-boundary bypass with high-impact control or data exposure. |
| High | Verified trust-boundary bypass requiring limited preconditions (for example, authenticated but unauthorized high-impact action), or exposure of OpenClaw-owned sensitive credentials. |
| Medium | Significant security weakness with practical impact but constrained exploitability or substantial prerequisites. |
| Low | Defense-in-depth findings, narrowly scoped denial-of-service, or hardening/parity gaps without a demonstrated trust-boundary bypass. |
3. Response
- Acknowledge receipt to the reporter (privately when sensitive). 2. Reproduce on supported releases and latest
main, then implement and validate a patch with regression coverage. 3. Critical/high: prepare patched release(s) as fast as practical. 4. Medium/low: patch in the normal release flow and document mitigation guidance.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
4. Communication and disclosure
Communicate through GitHub Security Advisories in the affected repository, release notes/changelog entries for fixed versions, and direct reporter follow-up on status and resolution.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
5. Recovery and follow-up
- Verify remediations in CI and release artifacts. 2. Run a short post-incident review: timeline, root cause, detection gap, prevention plan. 3. Add follow-up hardening/tests/docs tasks and track them to completion.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
관련 문서
주요 항목:
- Security policy — report scope and trust model.
- Threat model
실습 체크리스트
- 공식 문서와 로컬 버전을 대조합니다:
https://docs.openclaw.ai/security/incident-response - 관련 CLI는
openclaw --help및 하위 명령--help로 옵션을 확인합니다. - 설정 변경 시
openclaw config/openclaw doctor로 유효성을 검사합니다. - Gateway·채널·플러그인 변경 후에는 필요 시 Gateway를 재시작합니다.
관련 링크
이 가이드는 공식 문서를 한국어 학습용으로 재구성한 것입니다. 옵션 기본값·플래그 이름은 설치 버전에 따라 달라질 수 있습니다.