Skip to content

Security: mlaify/OpenContractRx

SECURITY.md

Security Policy

Supported versions

Security fixes will be prioritized for the latest main branch.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Instead:

  • Create a private report (preferred) via your hosting provider’s security advisory feature, or
  • Email the maintainers: security@opensift.org

Include:

  • Description of impact
  • Repro steps or PoC
  • Suggested mitigation (if you have one)

Security principles

  • Least privilege by default
  • Audit logging for sensitive actions
  • Avoid storing secrets in logs
  • Favor on-prem friendly components

There aren’t any published security advisories