Skip to content

Security: DeadWaveWave/opencove

Security

SECURITY.md

Security Policy πŸ”’

OpenCove takes the security of our users and their code very seriously.

Supported Versions

Version Supported Notes
0.1.x βœ… Yes Current Alpha
< 0.1.0 ❌ No Prototype releases

Reporting a Vulnerability

We strongly encourage you to report potential security vulnerabilities to our team.

πŸ›‘ Please DO NOT

  • Open a public GitHub Issue for a security vulnerability.
  • Disclose the vulnerability publicly before we have had a chance to address it.

βœ… Please DO

  • Send a private report via GitHub Security Advisories (if enabled) or email deadwavewave@gmail.com directly.
  • Include a Proof of Concept (PoC) or detailed reproduction steps.
  • Describe the impact of the vulnerability.

Response Timeline

We commit to the following response timeline:

  • Acknowledgement: Within 72 hours.
  • Assessment: We will confirm the issue and determine its severity.
  • Fix: We will work to patch the vulnerability as quickly as possible.
  • Disclosure: We will coordinate public disclosure with you.

Secrets & Data

If a security report involves leaked keys/tokens:

  1. Rotate any compromised credentials immediately.
  2. Redact sensitive information from screenshots or logs before sharing.

Thank you for helping keep OpenCove secure. πŸ›‘οΈ

There aren’t any published security advisories