Skip to content

Security: getdiby/OpenSet

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in OpenSet, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email security@openset.dev with:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Any potential impact

We will acknowledge your report within 48 hours and aim to provide a fix or mitigation plan within 7 days.

Scope

This policy covers:

  • The @diby/openset-types npm package
  • The @diby/openset-validator npm package
  • The @openset/codegen npm package
  • The OpenSet JSON Schema files
  • The openset.dev documentation website

Supported Versions

Version Supported
1.x Yes
< 1.0 No

There aren’t any published security advisories