Security · Responsible disclosure

Use a private channel for vulnerability reports.

Do not open a public issue for an unpatched vulnerability that could put users at risk.

Open-source project

Use GitHub private vulnerability reporting for the public RuleOak repository and follow its SECURITY.md for supported-version and reporting details.

Useful report content

Scope discipline

Internal hardening tests do not imply independent security certification, and a report about an external provider should be directed to that provider when RuleOak does not control the affected system.