Skip to content

Security: AcademySoftwareFoundation/OpenCue

SECURITY.md

Security and OpenCue

The OpenCue Technical Steering Committee (TSC) takes security very seriously. We strive to design secure software, and utilize continuous integration and code analysis tools to help identify potential vulnerabilities.

Reporting Vulnerabilities

Quickly resolving security related issues is a priority. If you think you've found a potential vulnerability in OpenCue, please report it by emailing opencue-tsc-private@lists.aswf.io. Only TSC members and ASWF project management have access to these messages.

Include detailed steps to reproduce the issue, and any other information that could aid an investigation. Someone will assess the report and make every effort to respond within 14 days.

CRA stewardship

This project is supported under the Linux Foundation CRA stewardship framework, as described at https://www.linuxfoundation.org/security. Security vulnerabilities should be reported through the mechanisms described below, which we will coordinate with our CRA steward. For actively exploited vulnerabilities and severe incidents that may require CRA escalation, please use the project’s emergency security reporting mechanisms as appropriate.

Outstanding Security Issues

None

Addressed Security Issues

None

There aren't any published security advisories