Skip to content

Security: rome-os/rome-apps

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest code on main and then released through the Rome App Store as appropriate. Older app versions may not receive separate patches.

Report a vulnerability

Please do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting and include:

  • The affected app, version, action, API route, or workflow.
  • Reproduction steps or a minimal proof of concept.
  • The security impact and required preconditions.
  • Any suggested mitigation, if known.

If private vulnerability reporting is temporarily unavailable, contact a Rome OS maintainer privately through the Rome Discord community and ask for a secure reporting channel. Do not post vulnerability details in a public channel.

Avoid accessing data that is not yours, disrupting Rome services, or publishing details before maintainers have had a reasonable opportunity to investigate and release a fix.

For ordinary bugs and usage questions, see SUPPORT.md.

There aren't any published security advisories