Skip to content

Security: rossoctl/autobench

Security

SECURITY.md

Security Policy

The rossoctl security policy — reporting process, response timelines, disclosure policy and supported versions — is maintained in the main project repository:

→ rossoctl/rossoctl/SECURITY.md

GitHub serves this file to any rossoctl repository that does not define its own, so the policy is written once and inherited everywhere rather than copied and left to drift.

Reporting a vulnerability — the short version

Do NOT open a public GitHub issue for a security vulnerability.

  1. GitHub Security Advisories (preferred). Report privately against the repository where you found the issue, via its Security → Advisories → Report a vulnerability tab. For the main project that is here.
  2. Email. rossoctl-maintainers@googlegroups.com
  3. Include: a clear description, steps to reproduce, affected versions, and potential impact.

You can expect acknowledgement within 48 hours and an initial assessment within 7 business days. Full timelines, the coordinated-disclosure policy and the security controls in place are in the linked policy above — read it before reporting.

There aren't any published security advisories