Skip to content

Security: ia-climateops/opencbam-core

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest released version of OpenCBAM Core (the opencbam package). Older versions are not maintained — please upgrade to the latest release before reporting an issue.

Reporting a vulnerability

Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Disclosing publicly before a fix is available puts users at risk.

Instead, report privately using GitHub's built-in private vulnerability reporting:

  1. Open the repository's Security tab.
  2. Choose Report a vulnerability, or go directly to https://github.com/ia-climateops/opencbam-core/security/advisories/new.
  3. Include the affected version and, where possible, reproduction steps or a proof of concept.

This creates a private security advisory visible only to you and the maintainers.

What to expect

  • Maintainers will acknowledge your report and begin assessing it as soon as they are reasonably able. This is a small open-source project, so we do not promise a fixed response or resolution time (no SLA); we commit to handling reports in good faith and responsibly.
  • We will work with you to confirm the issue, prepare a fix, and coordinate disclosure. Please give us a reasonable opportunity to address the problem before disclosing it publicly.
  • Reporters who wish to be credited will be acknowledged when the fix is released.

Scope

This policy covers security vulnerabilities in the OpenCBAM Core software — the opencbam package and this repository. Examples: a crash or unhandled error on untrusted input, unsafe file handling, or code that could corrupt data or execute untrusted content when running the tools against a supplied file.

Questions about regulatory correctness — whether a default value, benchmark, or formula matches the EU regulation — are not security vulnerabilities. Please raise those as normal GitHub issues so they can be discussed and verified in the open (see also SOURCES.md).

There aren't any published security advisories