Skip to content

Security: Juliusolsson05/openSEO

SECURITY.md

Security Policy

Reporting a vulnerability

Email security@openseo.dev. Do not open a public issue.

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment (what an attacker could do)

Response

  • We aim to acknowledge reports within 48 hours.
  • We will provide a fix timeline within 7 days.
  • Critical vulnerabilities will be patched as soon as possible.

Supported versions

Only the latest release on main is supported with security fixes.

Scope

This policy covers the OpenSEO application and its official Docker images. Third-party integrations, hosting infrastructure, and AI provider APIs are the operator's responsibility.

There aren't any published security advisories