Skip to content

Security: OpenCHAMI/image-builder

Security

SECURITY.md

Security Policy

We take the security of our OpenCHAMI seriously. This document explains how to report vulnerabilities and how we handle them.

🚨 Reporting a Vulnerability

If you believe you have found a security issue, please do not open a public issue.

Instead:

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (if available)

🛠 Our Process

  1. We will acknowledge receipt of your report within 48 hours.
  2. We will investigate and provide a target date for a fix (if confirmed).
  3. We will coordinate disclosure with you, ensuring you are credited if desired.
  4. A security advisory and patch release will be published once resolved.

📢 Public Disclosure

We strive for responsible disclosure. Security advisories will be published in:

  • GitHub Security Advisories
  • Release notes
  • Mailing list / community announcements

Thank you for helping keep our community safe!

There aren’t any published security advisories