Skip to content

Security: OctalMesh/OctalWeb

SECURITY.md

Security Policy

OctalWeb is a meta-repository that aggregates multiple independent submodules.

  • Submodules may be public or private
  • Each submodule may have its own release cycle
  • Issues, discussions, and security reports are centralized in this repository

Because of this, version-based support is not applicable at the platform level. Security handling is based on impact and scope, not version numbers.

Reporting a Vulnerability

If you discover a security vulnerability, do not open a public issue, discussion, or pull request. Instead, report it privately:

Please include as much of the following information as possible:

  • Type of issue (e.g. authentication bypass, RCE, SQL injection, XSS, CSRF, data exposure, logic flaw)
  • Affected submodule(s) or service(s)
  • Location of the issue (repository, branch, commit, or direct URL if public)
  • Configuration or environment assumptions
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if available)
  • Expected and actual behavior
  • Potential impact and realistic attack scenarios

Incomplete reports are still welcome, but detailed reports allow faster and more accurate triage.

Security reports are accepted in:

  • English
  • Ukrainian
  • Russian

Response Timeline

We aim to follow this process:

  • Acknowledgement: within 48 hours
  • Initial assessment: within 5 business days
  • Fix & disclosure: as soon as reasonably possible

Timelines may vary depending on severity and complexity.

Scope

This policy applies to:

  • OctalWeb platform
  • Official OctalWeb services and APIs
  • Repositories under the OctalMesh organization related to OctalWeb

Third-party services and dependencies follow their own security policies.

Security research helps keep OctalWeb reliable and boring - exactly how security should be

There aren't any published security advisories