| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability in OpenSOAR, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, email security@opensoar.app with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Impact assessment (if known)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Fix or mitigation: Depends on severity, but we aim for:
- Critical: 72 hours
- High: 1 week
- Medium/Low: Next release cycle
We follow coordinated disclosure:
- Reporter notifies us privately
- We confirm and assess the vulnerability
- We develop and test a fix
- We release the fix and publish an advisory
- Reporter is credited (unless they prefer anonymity)
We ask that you give us reasonable time to address the issue before public disclosure.
This policy applies to:
opensoar-core(API, worker, UI, deployment configs)opensoar-sdk- Official Docker images on GHCR
Third-party integrations should be reported to their respective maintainers.