Security fixes are provided for the latest released version of OpenCBAM Core
(the opencbam package). Older versions are not maintained — please upgrade to
the latest release before reporting an issue.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Disclosing publicly before a fix is available puts users at risk.
Instead, report privately using GitHub's built-in private vulnerability reporting:
- Open the repository's Security tab.
- Choose Report a vulnerability, or go directly to https://github.com/ia-climateops/opencbam-core/security/advisories/new.
- Include the affected version and, where possible, reproduction steps or a proof of concept.
This creates a private security advisory visible only to you and the maintainers.
- Maintainers will acknowledge your report and begin assessing it as soon as they are reasonably able. This is a small open-source project, so we do not promise a fixed response or resolution time (no SLA); we commit to handling reports in good faith and responsibly.
- We will work with you to confirm the issue, prepare a fix, and coordinate disclosure. Please give us a reasonable opportunity to address the problem before disclosing it publicly.
- Reporters who wish to be credited will be acknowledged when the fix is released.
This policy covers security vulnerabilities in the OpenCBAM Core software —
the opencbam package and this repository. Examples: a crash or unhandled error
on untrusted input, unsafe file handling, or code that could corrupt data or
execute untrusted content when running the tools against a supplied file.
Questions about regulatory correctness — whether a default value, benchmark,
or formula matches the EU regulation — are not security vulnerabilities.
Please raise those as normal
GitHub issues so they can
be discussed and verified in the open (see also SOURCES.md).