Skip to content

Security: juanitto-maker/GuardOS

Security Navigation

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in GuardOS, please report it privately via GitHub:

πŸ‘‰ Report a vulnerability

This ensures responsible disclosure and coordinated fixes with the core team.


Coordination Process

  • Vulnerabilities are reviewed privately
  • Fixes are published along with public advisories
  • Contributors may be credited if they opt in

Security Tools in Use

GuardOS is protected by the following GitHub security features:

  • πŸ” Private vulnerability reporting
  • πŸ“’ Security advisories
  • 🧠 CodeQL static code analysis
  • πŸ€– Copilot Autofix (for core and third-party tools)
  • πŸ“¦ Dependabot alerts & updates
  • πŸ•΅οΈ Secret scanning

These help maintain security and transparency for the community.


Scope

This policy applies to the core GuardOS project, build pipeline, and packaging.
Third-party dependency issues should be reported upstream if possible.