The Open Device Partnership project welcomes the responsible disclosure of vulnerabilities.
Report security bugs privately through a GitHub Security Advisory. Do not report vulnerabilities in a public issue.
Your initial contact will be acknowledged within 48 hours, and you will receive a more detailed response within 96 hours indicating the next steps. The security team will endeavor to provide progress updates at least every five working days.
- A private channel is established and a primary handler is assigned.
- The report is confirmed and affected versions are identified. If an embargo is needed, its scope and expected completion date are agreed upon.
- The code is audited for similar problems.
- Fixes are prepared for maintained releases. Embargoed fixes remain private until coordinated disclosure.
- Fixes are published and new releases are made available.
This process can take time when coordination with maintainers of other projects is required. We will handle reports as promptly as possible while following a consistent disclosure process.
A security issue may be embargoed when immediate disclosure would endanger users, when a fix requires coordination among multiple parties, or when proper analysis requires additional time.
If an embargo is needed, we will work with the reporter to establish a reasonable completion date and identify who needs access to the report.