At OpenTab, we’re passionate about building secure open source projects that students and developers can trust. This policy outlines how to report vulnerabilities responsibly, keeping our community and projects safe.
We provide security updates for the latest stable release of each OpenTab project. Older versions may not receive patches, so please update before reporting.
| Project | Supported Versions |
|---|---|
| All OpenTab Projects | Latest release (check repos for specifics) |
See OpenTabOrg for release details.
Found a security issue? Here’s how to report it safely:
- Don’t File Public Issues: Public disclosure could harm users.
- Email Us: Send details to security@opentab.org (use PGP for extra security—see below).
- Provide Details:
- Project and version affected (e.g., OpenTab-Web v1.0.0).
- Type of issue (e.g., XSS, data leak).
- Steps to reproduce.
- Potential impact (e.g., “exposes user data”).
- Suggested fix (optional).
- Expect a Response: We’ll reply within 48 hours to confirm and discuss next steps.
Encrypt your report with our PGP key for secure communication:
- Key ID:
0xABCD1234EFGH5678 - Fingerprint:
ABCD 1234 EFGH 5678 9012 3456 7890 ABCD EFGH 1234 - Download: security@opentab.org.asc
- We’ll acknowledge your report within 48 hours.
- Our security team will assess the issue’s severity and impact.
- We’ll work with you to validate and fix the vulnerability.
- Once resolved, we’ll release a patch and credit you (unless you prefer anonymity).
- If the issue isn’t valid, we’ll explain why.
Please:
- Give us up to 90 days to fix the issue before public disclosure.
- Avoid exploiting vulnerabilities beyond proof-of-concept.
- Respect user privacy and data.
We’ll:
- Act quickly to address valid issues.
- Credit you in release notes (e.g., “Thanks to @CodeNinja for reporting CVE-2025-1234!”).
- Add you to our Security Hall of Fame (coming soon!).
No known vulnerabilities at this time. Check Releases for updates.
Contact security@opentab.org or message us privately in Telegram.
Thanks for keeping OpenTab secure! You’re our favorite kind of code wrangler. 🛡️
“Secure code is happy code!” — OpenTab Security Squad