Skip to content

Security: opencitadel/OARS

Security

SECURITY.md

Security Policy

What belongs here

This repository holds a specification, a ratings dataset, and the tooling that validates and publishes them. Report here:

  • A defect in the tooling or site that could harm someone running it
  • A supply-chain concern with this repository or its release artifacts
  • A rating or model flaw whose public discussion would meaningfully help an attacker before defenders can react

Please report responsibly rather than opening a public issue for those.

What does not belong here

Vulnerabilities in Microsoft products or services — including Microsoft Entra ID, Microsoft Graph, and the permissions this standard describes — go to the Microsoft Security Response Center, not to us. We are documenting how risky permissions are, not maintaining the platform that grants them.

Ordinary disagreements about a rating are not security issues. A permission you believe is under-rated is a rating change request and benefits from being discussed in the open.

How to report

Use GitHub's private vulnerability reporting:

Report a vulnerability →

If that is unavailable to you, contact a maintainer directly and ask for a private channel. Do not include details in the first public message.

Please include what you found, how to reproduce it, what an attacker could achieve, and how you would like to be credited.

What to expect

Acknowledgement Within 3 working days
Initial assessment Within 10 working days
Fix or mitigation Depends on severity; we will keep you updated
Credit Offered by default, declined on request

We are volunteers. We will be honest with you about timelines rather than promise a response time we cannot meet.

Disclosure

We follow coordinated disclosure. We will agree a disclosure date with you, publish an advisory when a fix ships, and credit you unless you prefer otherwise. Please give us a reasonable window before publishing — 90 days is our default, and we will usually be much faster.

There aren't any published security advisories