Skip to content

Security: OpenSyntaxHQ/.github

Security

SECURITY.md

Security Policy

Supported Versions

Security updates are provided for the latest major version of each project. Check individual repository documentation for specific version support.

Reporting a Vulnerability

Do not open public issues for security vulnerabilities.

Report security issues via:

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

Stage Timeframe
Initial acknowledgment 48 hours
Preliminary assessment 7 days
Resolution target 30 days (may vary by severity)

Process

  1. Report received and acknowledged
  2. Vulnerability verified and assessed
  3. Fix developed and tested
  4. Coordinated disclosure (if applicable)
  5. Security advisory published
  6. Credit given to reporter (unless anonymity requested)

Disclosure Policy

We follow responsible disclosure practices:

  • We'll work with you to understand and resolve the issue
  • We'll credit reporters in security advisories
  • We ask that you don't disclose publicly until we've had time to address the issue

Scope

This policy covers all repositories under OpenSyntaxHQ. Third-party dependencies should be reported to their respective maintainers.


Thanks for helping keep our projects safe.

There aren’t any published security advisories