Skip to content

Security: tortuvshin/open-apps

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report security issues in this repository through a private GitHub security advisory:

https://github.com/tortuvshin/open-apps/security/advisories/new

Do not open a public issue for an undisclosed vulnerability. You may also contact an active maintainer using the email address in repository commit metadata.

We aim to acknowledge reports within three working days, provide a triage update within seven, and agree on a disclosure timeline with the reporter.

Scope

The Astro application, Grove integration, GitHub Actions, deployment configuration, and committed dependencies are in scope. The apps listed in data/records/ are external projects; report vulnerabilities in those apps to their own maintainers.

Only the latest commit on main receives security fixes.

There aren't any published security advisories