Skip to content

Security: openAMRobot/openamr

Security

SECURITY.md

Security Policy

Purpose

This document defines the OpenAMRobot approach to responsible security reporting and disclosure.


Reporting Vulnerabilities

If you discover a security vulnerability, please avoid publicly disclosing it immediately.

Instead:

  • open a private security advisory if available
  • contact maintainers through appropriate channels
  • provide technical details sufficient for reproduction

Scope

Security concerns may include:

  • ROS vulnerabilities
  • remote control vulnerabilities
  • networking issues
  • unsafe default configurations
  • authentication weaknesses
  • unsafe firmware behavior
  • robotics safety issues
  • AI-related security concerns

Responsible Disclosure

The organization aims to:

  • acknowledge reports reasonably quickly
  • investigate reported issues
  • coordinate responsible disclosure
  • publish fixes when practical

Experimental Nature

OpenAMRobot projects are experimental and research-oriented.

No software or hardware should be assumed safe for:

  • industrial deployment
  • medical use
  • safety-critical systems
  • autonomous public operation

without independent validation and certification.


User Responsibility

Users are responsible for:

  • validating safety
  • regulatory compliance
  • deployment suitability
  • integration testing
  • operational safety

Supported Versions

Security support expectations may vary by repository and project maturity.

Repositories should document supported versions when applicable.


Policy Updates

This policy may evolve as the ecosystem grows.

There aren't any published security advisories