If you discover a security vulnerability in the OSV Framework, please report it by creating a private security advisory or by contacting the maintainers directly.
Please do not report security vulnerabilities through public GitHub issues.
-
GitHub Security Advisory: Use GitHub's private vulnerability reporting feature
- Go to the repository's Security tab
- Click "Report a vulnerability"
- Fill out the advisory form
-
Direct Contact: For sensitive security issues, use GitHub's private reporting feature above
- For non-sensitive matters, create a regular issue in the repository
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggested fixes (if available)
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
When implementing OSV Framework in your project:
- Keep Dependencies Updated: Regularly update any dependencies
- Validate Input: Always validate and sanitize user input
- Secure Calculations: Ensure calculation logic cannot be manipulated
- Access Control: Implement proper access control for sponsorship management
- Audit Trail: Maintain logs of OSV calculations and sponsorship assignments
When contributing to the OSV Framework:
- Follow Security Guidelines: Adhere to secure coding practices
- Review Dependencies: Check for vulnerabilities in any new dependencies
- Test Thoroughly: Include security testing in your contributions
- Document Security Implications: Note any security considerations in PRs
We follow responsible disclosure practices:
- Acknowledgment: We'll acknowledge receipt of your vulnerability report within 48 hours
- Assessment: We'll assess the vulnerability and determine severity
- Fix Development: We'll work on a fix in a private branch
- Public Disclosure: After the fix is released, we'll publicly disclose the vulnerability with appropriate credit to the reporter (if desired)
We appreciate security researchers who help keep the OSV Framework and its users safe. Security contributors will be:
- Acknowledged in our SECURITY.md file (with permission)
- Mentioned in release notes for security fixes
- Eligible for OSV credits if they wish to sponsor related improvements
Thank you for helping keep the OSV Framework secure!
Created by Waren Gonzaga under WG Tech Labs