Skip to content

Security: suped-com/openbimi

SECURITY.md

Security policy

Supported versions

OpenBIMI is in early development and has not published a stable release. Security fixes are applied to the latest code on main and the production deployment at openbimi.com.

Report a vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories.

Include, when possible:

  • the affected page, component, or commit;
  • a clear description of the impact;
  • reproduction steps or a proof of concept;
  • suggested remediation; and
  • whether the issue is already public or being actively exploited.

Do not open a public issue, discussion, or pull request for an unpatched vulnerability. Do not access data that does not belong to you, disrupt the service, or perform destructive testing.

We aim to acknowledge a complete report within three business days. We will share updates as triage and remediation progress and will coordinate disclosure with the reporter when appropriate.

Scope

The source in this repository and the production service at openbimi.com are in scope. Vulnerabilities in third-party services should be reported directly to those providers unless the issue is caused by OpenBIMI's integration with them.

There aren't any published security advisories