Skip to content

Security: open-operational-state/.github

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any Open Operational State repository, please report it responsibly.

Do not open a public issue.

Instead, send an email to:

security@open-operational-state.org

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The repository and file(s) affected
  • Any potential impact you have identified

Response Timeline

We will acknowledge receipt of your report within 3 business days and aim to provide an initial assessment within 10 business days.

Scope

This policy applies to all repositories under the open-operational-state GitHub organization:

  • governance
  • status-spec
  • status-conformance
  • status-tooling

Disclosure

We follow a coordinated disclosure process. We will work with you to understand and address the issue before any public disclosure is made.

Recognition

We appreciate the efforts of security researchers and will acknowledge reporters (with their permission) in any public advisory related to the reported issue.

There aren’t any published security advisories