Skip to content

Security: opendecree/decree

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in OpenDecree, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please report it via GitHub Security Advisories with:

  1. A description of the vulnerability
  2. Steps to reproduce
  3. The potential impact
  4. Any suggested fix (optional)

You should receive a response within 48 hours. We will work with you to understand and address the issue before any public disclosure.

Supported Versions

Version Supported
latest Yes

Scope

This policy covers the OpenDecree server, CLI, and SDK packages in this repository.

There aren’t any published security advisories