Skip to content

Security: ruKurz/oi-architecture

Security

SECURITY.md

Security Policy

Supported Versions

This project is in active development. Security fixes are applied to the latest version only.

Version Supported
latest (main branch)
older releases

Reporting a Vulnerability

Do not report security vulnerabilities via public GitHub Issues.

Please report vulnerabilities by email to: kurz@vnc-online or via GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Fill in the details

What to Include

  • Description of the vulnerability and affected component
  • Steps to reproduce
  • Potential impact
  • Suggested fix (optional)

Response Timeline

Step Target
Acknowledgement Within 5 business days
Assessment Within 14 days
Fix or mitigation As soon as feasible, depending on severity

Scope

This repository contains:

  • A static website (GitHub Pages) — primarily front-end/HTML/CSS/JS
  • Markdown documentation and architecture content

Out of scope: theoretical vulnerabilities with no practical exploit path, issues in upstream dependencies that have no impact on this project.

There aren't any published security advisories