Skip to content

Security: openai/openai-dotnet

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities privately through OpenAI's Bugcrowd program. The program page contains OpenAI's vulnerability disclosure guidelines and scope.

Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

This policy applies to the source code in this repository and the official OpenAI NuGet package published from it.

For vulnerabilities in other OpenAI products or services, use the same OpenAI Bugcrowd program and select the appropriate target.

What to include

When reporting a vulnerability, include:

  • The affected package or product and version, or the affected commit.
  • A clear description of the potential impact.
  • Sanitized steps to reproduce the issue or a minimal proof of concept.
  • The .NET runtime, target framework, and operating system, when relevant.
  • Any known mitigations or workarounds.

Do not include live credentials, API keys, customer data, or unredacted sensitive logs.

Coordinated disclosure

Please give the maintainers a reasonable opportunity to investigate and address the issue before public disclosure.

There aren't any published security advisories