Do not open a public GitHub issue for security vulnerabilities.
Use GitHub's private vulnerability reporting feature or contact maintainers directly.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
This policy covers:
- The EDP specification (SPEC.md)
- JSON schemas
- Example implementations
For vulnerabilities in specific EDP registry implementations, contact the respective operators.
See Section 6 of SPEC.md for security considerations when implementing EDP.