Report a vulnerability privately through this repository's GitHub "Report a vulnerability" form (Security tab → Advisories) — never as a public issue.
You should expect an acknowledgement within 7 days.
This policy covers this repository (opensoft/openDox, the assembly root)
only. Each of the two legs — opensoft/openDox-spec and
opensoft/openDox-code — is separately clonable and carries its own
SECURITY.md with the same policy, scoped to itself.