This policy applies to every repository in the otee-as organization.
Do not open a public issue. Do not put details in a pull request.
- Members of the organization: open a Linear issue in the OPS project
with the
securitylabel, or contact the DevSecOps lead (@jp-devops-ot) or the CTO (@radek-otee) directly. - External reporters: use the contact on https://otee.com.
Include: the repository, the version or commit, the steps to reproduce, and the impact you expect. We confirm receipt within two working days.
- We confirm the report and assess severity.
- We fix it on a maintenance line if it affects a released version, and on
main. - We tell you when the fix is released. We credit you if you want that.
- All repositories in the organization, including forks we maintain.
- Secrets in git history: report them; we rotate the secret first, then clean the history.
- The organization's security policies live in the
otee-cybersec-policyrepository (members only). - Dependency alerts are enabled on every managed repository.