FDC3 Sail adheres to the FINOS Security Vulnerabilities Responsible Disclosure Policy. If you believe you have found a security vulnerability in FDC3 Sail, please report it privately using one of the methods below — do not open a public GitHub Issue.
- GitHub private vulnerability reporting (preferred): use the "Report a vulnerability" button under this repository's Security tab.
- Email: the maintainers listed in MAINTAINERS.md, cc security@finos.org.
We will acknowledge your report within 5 working days, give a triage outcome within 14 days, and update you at least every 30 days while a confirmed issue is open. Fixes are released and disclosed in accordance with the FINOS policy above.
Vulnerabilities in the FDC3 standard itself should be reported to finos/FDC3.