Do not open a public issue.
Use GitHub's private vulnerability reporting on this repository (Security → Report a vulnerability), or email info@origindev.com with Subject: "OSDS SECURITY"
Please include a description, reproduction steps, affected versions, and impact.
- Acknowledgement within 3 business days
- An assessment and remediation plan within 10 business days
- Credit in the release notes unless you prefer otherwise
In scope: the OSDS core, bundled adapters, and the reference Docker deployment.
Out of scope: vulnerabilities in third-party services an operator connects, and misconfiguration of a self-hosted deployment.
Security reports are handled by humans. The repository automation is prohibited from processing, triaging, or commenting on them.