Skip to content

Security: emphereio/ovrse

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in OVRSE, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting to submit your report. Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

We will acknowledge receipt within 48 hours and provide a detailed response within 7 days.

Scope

This policy covers:

  • The OVRSE specification documents
  • The reference CLI implementation (cmd/, pkg/)
  • Example templates and KB entries

Intelligence Feedback

For issues with CVE intelligence data (incorrect verdicts, wrong remediation steps, etc.), please use the Intel Feedback issue template. These are not security vulnerabilities in OVRSE itself.

Supported Versions

Version Supported
0.x Yes

We will provide security updates for the latest release.

There aren't any published security advisories