Skip to content

Security: AsobaCloud/odse

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are prioritized for the latest published release on main.

Reporting a Vulnerability

Do not open public GitHub issues for security vulnerabilities.

Report privately to:

Please include:

  1. Affected component (schema, transform, runtime, tooling).
  2. Reproduction steps or proof of concept.
  3. Impact assessment.
  4. Suggested remediation (if available).

Response Expectations

  • Initial acknowledgment: within 3 business days.
  • Triage and severity assessment: within 7 business days.
  • Remediation timeline: communicated after triage.

Disclosure

We aim for coordinated disclosure:

  1. Confirm issue.
  2. Prepare fix and tests.
  3. Publish patch release and notes.
  4. Publicly disclose once remediation is available.

There aren’t any published security advisories