Skip to content

Security: databricks-solutions/databricks-forge

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue. Submit the report through GitHub private vulnerability reporting.

Include a description, reproduction steps or proof of concept, potential impact, and any suggested remediation. Remove customer data and credentials.

The maintainer will acknowledge a complete report on a best-effort basis. Coordinated disclosure timing will be agreed through the private advisory.

Supported version

Only the latest commit on main is supported.

Scope

This policy covers code in this repository. Databricks platform vulnerabilities must be reported through Databricks Security.

Security Architecture

See Security Architecture for Forge's data flows, authentication model, and mitigations.

There aren't any published security advisories