Skip to content

Security: AOSSIE-Org/CarbonFootprint-API

Security

SECURITY.md

Security Policy

Thank you for helping keep our projects and community secure. We take security vulnerabilities seriously and appreciate responsible disclosure.

Supported Versions

Security updates are provided for actively maintained repositories. Support varies by repository depending on its maintenance status.

Repository Status Security Support
Actively Maintained
Security-Fixes Only
Archived / Unmaintained

Please refer to the individual repository documentation if a project has its own security support policy.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability, please do not open a public GitHub issue.

Instead, report it privately by:

  • Opening a GitHub Security Advisory (preferred), if enabled for the repository.
  • Contacting the maintainers via the organization's security contact (ending with @aossie.org only)
  • If neither option is available, contact the repository maintainers through the project's official communication channels.

When reporting a vulnerability, please include:

  • A clear description of the issue.
  • Steps to reproduce the vulnerability.
  • The affected repository, branch, commit, or version.
  • Proof of concept or screenshots, if applicable.
  • Any suggested mitigation or fix (optional).

Response Process

We aim to:

  • Acknowledge receipt of your report within 5 business days.
  • Keep you informed about the investigation and remediation process.
  • Validate and prioritize confirmed vulnerabilities based on their impact.
  • Coordinate disclosure and release a fix before public disclosure whenever possible.

Responsible Disclosure

Please allow us reasonable time to investigate and remediate reported vulnerabilities before publicly disclosing them.

We kindly ask that you:

  • Do not publicly disclose the vulnerability until a fix is available.
  • Avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the issue.
  • Make a good-faith effort to avoid privacy violations, service disruption, or data destruction.

We greatly appreciate the efforts of security researchers and contributors who help improve the security of our open-source projects.

There aren't any published security advisories