Thank you for helping us keep the OpenAI .NET library secure.
Do not report security vulnerabilities through public GitHub issues or pull requests.
Please report suspected vulnerabilities through OpenAI's Bugcrowd program. The program page contains OpenAI's vulnerability disclosure guidelines and scope.
When possible, include:
- the affected package version or commit;
- the .NET runtime, target framework, and operating system;
- steps to reproduce the issue or a minimal proof of concept;
- the potential impact; and
- any known mitigations or workarounds.
Please allow OpenAI a reasonable opportunity to investigate and address the issue before sharing it publicly.
This policy applies to the source code in this repository and the official
OpenAI NuGet package published from
it.
For vulnerabilities in other OpenAI products or services, use the same OpenAI Bugcrowd program and select the appropriate target.