Skip to content

Security: OctalMesh/.github

SECURITY.md

Security Policy

This is a default, organization-wide security policy for OctalMesh repositories. It applies to repositories that do not provide their own SECURITY.md.

Reporting a Vulnerability

If you discover a security vulnerability, do not open a public issue, discussion, or pull request. Instead, report it privately:

Please include as much of the following information as possible:

  • Description of the issue
  • Affected component(s) or service(s)
  • Repository and file paths involved
  • Steps or conditions required to reproduce the issue
  • Potential impact
  • Suggested mitigation, if available

Incomplete reports are still welcome, but detailed reports allow faster and more accurate triage.

Security reports are accepted in:

  • English
  • Ukrainian
  • Russian

Response Timeline

We aim to follow this process:

  • Acknowledgement: within 48 hours
  • Initial assessment: within 5 business days
  • Fix & disclosure: as soon as reasonably possible

Timelines may vary depending on severity and complexity.

Scope

This default policy applies to:

  • Source code, workflows, and configurations in repositories without their own security policy
  • Organization-wide templates and shared configuration

Application-specific vulnerabilities should be reported according to the SECURITY.md of the affected repository. Third-party services and dependencies follow their own security policies.

Security research helps keep OctalWeb reliable and boring - exactly how security should be

There aren’t any published security advisories