Skip to content

Security: davidichalfyorov-wq/openxiv

Security

SECURITY.md

Security

Report private vulnerabilities to davidich.alfyorov@gmail.com.

Expected first response: 72 hours.

Supported versions: the main branch only.

Please do not open a public issue for a live vulnerability. Include the affected path, impact, reproduction steps, and any logs that do not contain secrets.

OpenXiv does not ask reporters to rotate OpenXiv secrets. The operator handles credential changes after confirming the issue.

There aren't any published security advisories