Skip to content

Security: outscale/osc-sdk-python

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in this project, please do not open a public GitHub issue.

Whenever possible, use GitHub's Private Vulnerability Reporting feature:

  1. Go to the Security and quality tab of the repository.
  2. Select Report a vulnerability.
  3. Provide as much information as possible about the issue.

This is the preferred way to report security vulnerabilities.

Alternative Contact

If Report a vulnerability is not available for this repository, you can contact us through one of the following channels:

Please do not post vulnerability details publicly on Discord. Contact us first so that we can continue the discussion privately.

What to Include

When reporting a vulnerability, please include as much relevant information as possible, such as:

  • A description of the vulnerability
  • The affected component or version
  • Steps to reproduce the issue
  • The potential impact
  • Any proof of concept, logs, or screenshots that may help us understand the issue
  • A suggested fix or mitigation, if you have one

Responsible Disclosure

We ask that you give us a reasonable amount of time to investigate and address the vulnerability before publicly disclosing it.

We appreciate security researchers and community members who take the time to responsibly report potential security issues.

Security-related GitHub Issues

Public GitHub issues should not be used to report vulnerabilities.

If a security-related issue is opened publicly, we may close or remove it and ask the reporter to use the private vulnerability reporting process instead.

There aren't any published security advisories