Skip to content

Security: yangheng95/opencorvus

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest tagged OpenCorvus beta release. Older beta releases may be asked to upgrade before a fix is evaluated.

Reporting a vulnerability

Do not report vulnerabilities in a public issue, discussion, pull request, log, or screenshot.

Use GitHub private vulnerability reporting and include:

  • the affected version and component;
  • the impact and realistic attack conditions;
  • minimal reproduction steps or a proof of concept;
  • any known mitigations; and
  • whether the report may be shared with upstream maintainers.

Remove unrelated credentials, personal data, and proprietary project content. The maintainers will acknowledge the report through the advisory, investigate it, and coordinate disclosure after a fix or mitigation is available.

If private vulnerability reporting is unavailable, contact the repository owner through the contact method published on their GitHub profile and do not disclose technical details publicly.

There aren't any published security advisories