Skip to content

Security: juanitto-maker/GuardOS

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in GuardOS, please report it privately via GitHub:

👉 Report a vulnerability

This ensures responsible disclosure and coordinated fixes with the core team.


Coordination Process

  • Vulnerabilities are reviewed privately
  • Fixes are published along with public advisories
  • Contributors may be credited if they opt in

Security Tools in Use

GuardOS is protected by the following GitHub security features:

  • 🔐 Private vulnerability reporting
  • 📢 Security advisories
  • 🧠 CodeQL static code analysis
  • 🤖 Copilot Autofix (for core and third-party tools)
  • 📦 Dependabot alerts & updates
  • 🕵️ Secret scanning

These help maintain security and transparency for the community.


Scope

This policy applies to the core GuardOS project, build pipeline, and packaging.
Third-party dependency issues should be reported upstream if possible.

There aren’t any published security advisories