Skip to content

Security: tabletop-commons/OpenTabletop

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Instead, please report them via GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository
  2. Click Report a vulnerability
  3. Fill out the form with details about the vulnerability

Alternatively, email security@opentabletop.org with:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 7 days
  • Fix: Depends on severity; critical issues targeted within 14 days

Scope

This policy covers:

  • The OpenAPI specification (spec/)
  • Reference server implementation (reference/)
  • Official SDKs (sdks/)
  • CI/CD pipelines and infrastructure

Disclosure

We follow coordinated disclosure. We will work with reporters to agree on a disclosure timeline, typically 90 days from the initial report.

There aren’t any published security advisories