Skip to content

Security: doubleopen-io/.github

Security

SECURITY.md

Security Policy

Double Open adheres to the Double Open Vulnerability Handling Policy.

How to report a vulnerability

If you think you have found a vulnerability in this repository or in a service operated by Double Open, please report it to us through coordinated disclosure.

Please do not report security vulnerabilities through public issues, discussions, or pull requests.

Instead, report it using one of the following ways:

  • Email security@doubleopen.io. This address reaches a small group of Double Open staff responsible for security.
  • Report it privately on GitHub via https://github.com/doubleopen-io/[repository]/security/advisories/new (replace [repository] with the repository name, for example dos).

We will acknowledge your report within three business days and keep you informed of our progress. See the policy linked above for what to expect.

Please include as much of the information listed below as you can to help us understand and resolve the issue:

  • The type of issue (e.g. injection, authentication bypass, path traversal)
  • Affected version(s), commit, or the URL of the affected service
  • Impact of the issue, including how an attacker might exploit it
  • Step-by-step instructions to reproduce the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Configuration required to reproduce the issue
  • Log files related to the issue (if possible)
  • Proof-of-concept or exploit code (if possible)

Forks of upstream projects

Several repositories in this organization are forks of upstream projects (for example ORT and ORT Server). If the issue is in the upstream code, please report it to the upstream project's security contact. If you are unsure, or the issue is in changes made by Double Open, report it to us and we will coordinate with upstream.

Supported versions

Unless a repository states otherwise, security fixes are provided only for the latest release or the default branch.

There aren't any published security advisories