Security · Responsible disclosure
Use a private channel for vulnerability reports.
Do not open a public issue for an unpatched vulnerability that could put users at risk.
Open-source project
Use GitHub private vulnerability reporting for the public RuleOak repository and follow its SECURITY.md for supported-version and reporting details.
Useful report content
- affected version or commit;
- reproduction steps or proof of concept;
- expected versus observed security boundary;
- impact and prerequisites;
- any suggested mitigation, if known.
Scope discipline
Internal hardening tests do not imply independent security certification, and a report about an external provider should be directed to that provider when RuleOak does not control the affected system.