Skip to content

Security: thinkdj/ottabase

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Preferred reporting channels:

  1. Email security@ottabase.com
  2. GitHub private vulnerability reporting (Security Advisories) for this repository

If email is unavailable, use GitHub private reporting to avoid public disclosure.

What to Include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions and components
  • Potential impact assessment
  • Any suggested fixes (optional)

Response Timeline

Stage Timeframe
Acknowledgement Within 48 hours
Initial assessment Within 7 days
Fix and disclosure Coordinated with reporter

Supported Versions

Version Supported
latest (main) ✅ Yes
older commits ❌ No

Credit

We appreciate responsible disclosure. Security researchers who report valid vulnerabilities will be credited in the release notes (unless they prefer to remain anonymous).

Scope

This policy applies to all packages and applications within the Ottabase monorepo. Third-party dependencies are excluded but will be escalated to their respective maintainers.

There aren't any published security advisories