This security policy applies to the Patchwork OSS challenges repository and the Patchwork OSS organization infrastructure only.
If you discover a security vulnerability in this repository or in any Patchwork OSS infrastructure, please report it responsibly.
Do NOT open a public GitHub Issue for security vulnerabilities.
Instead, please report security concerns by emailing the Patchwork OSS maintainers or by using GitHub's private vulnerability reporting feature if available on this repository.
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fix (optional)
- Acknowledgment: Within 48 hours
- Assessment: Within 7 days
- Resolution: Depends on severity and complexity
This security policy does not cover:
- External open-source projects referenced in our challenges. If you find a security vulnerability in an external project, report it to that project's maintainers using their own security policy — not to Patchwork OSS.
- General bugs in this repository that are not security-related. For those, please open a regular Issue.
This repository primarily contains documentation and community configuration. Security concerns here typically involve:
- Exposed credentials or secrets in repository files
- Malicious links in challenge files
- GitHub Actions workflow vulnerabilities
- Social engineering or impersonation concerns
We take all reports seriously regardless of severity.