If you discover a security vulnerability in OVRSE, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please use GitHub's private vulnerability reporting to submit your report. Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
We will acknowledge receipt within 48 hours and provide a detailed response within 7 days.
This policy covers:
- The OVRSE specification documents
- The reference CLI implementation (
cmd/,pkg/) - Example templates and KB entries
For issues with CVE intelligence data (incorrect verdicts, wrong remediation steps, etc.), please use the Intel Feedback issue template. These are not security vulnerabilities in OVRSE itself.
| Version | Supported |
|---|---|
| 0.x | Yes |
We will provide security updates for the latest release.