odoo-forge is pre-1.0. Only the latest commit on main receives security fixes.
| Version | Supported |
|---|---|
main |
✅ |
| anything else | ❌ |
Please do not open a public issue for security problems.
Use GitHub private vulnerability reporting instead. Reports are acknowledged within a week.
Areas of particular interest:
- Credential injection into spawned subprocesses (Git, Docker, PostgreSQL, GHCR)
- SOPS/age credential materialization and rotation
- Masking of database dumps
- Anything that could leak a secret into logs, process listings, or error messages
This policy covers the code in this repository only. Vulnerabilities in Odoo itself should be reported to Odoo's security team.