Skip to content

Security: openjobspec/ojs-java-sdk

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in the OJS Java SDK, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please report vulnerabilities by emailing security@openjobspec.org.

Include the following information:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 5 business days
  • Fix & Disclosure: Coordinated with the reporter

Scope

This policy applies to the OJS Java SDK codebase. For vulnerabilities in the OJS specification itself or other OJS projects, please report them to the appropriate repository.

Recognition

We appreciate security researchers who help keep our project safe. Contributors who report valid security issues will be acknowledged in our release notes (unless they prefer to remain anonymous).

There aren’t any published security advisories