Skip to content

Security: OSSAfrica/.github

SECURITY.md

Security Policy

Our Commitment

At Open Source & Security Africa (OSSAfrica), security is at the core of our mission. We are committed to ensuring the security and integrity of our projects and take all reports of security vulnerabilities seriously.

Reporting a Vulnerability

If you discover a security vulnerability in any OSS-Africa project, please report it responsibly by following these steps:

  1. Do not disclose the vulnerability publicly until it has been addressed
  2. Create a private security advisory in the affected repository, or
  3. Contact the maintainers directly through GitHub's private messaging

What to Include in Your Report

To help us understand and address the issue efficiently, please provide:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact of the vulnerability
  • Any suggestions for remediation (if available)

Response Process

When you report a vulnerability:

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Assessment: Our team will assess the vulnerability and determine its severity
  3. Resolution: We will work on a fix and keep you informed of our progress
  4. Disclosure: Once resolved, we will coordinate with you on responsible disclosure

Security Best Practices

As a community focused on security, we encourage all contributors to:

  • Follow secure coding practices
  • Keep dependencies up to date
  • Report potential security issues promptly
  • Participate in security reviews when requested

Scope

This security policy applies to all repositories maintained by the OSS-Africa organization on GitHub.

Recognition

We appreciate security researchers and community members who help improve the security of our projects. Contributors who report valid security issues may be acknowledged in our release notes (with their permission).

Thank you for helping keep OSS-Africa and the broader open source community secure!

There aren’t any published security advisories