Skip to content

Security: Patchwork-OSS/challenges

Security

SECURITY.md

Security Policy

Scope

This security policy applies to the Patchwork OSS challenges repository and the Patchwork OSS organization infrastructure only.

Reporting a Vulnerability

If you discover a security vulnerability in this repository or in any Patchwork OSS infrastructure, please report it responsibly.

Do NOT open a public GitHub Issue for security vulnerabilities.

Instead, please report security concerns by emailing the Patchwork OSS maintainers or by using GitHub's private vulnerability reporting feature if available on this repository.

What to Include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fix (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 7 days
  • Resolution: Depends on severity and complexity

What Is NOT Covered

This security policy does not cover:

  • External open-source projects referenced in our challenges. If you find a security vulnerability in an external project, report it to that project's maintainers using their own security policy — not to Patchwork OSS.
  • General bugs in this repository that are not security-related. For those, please open a regular Issue.

Supported Versions

This repository primarily contains documentation and community configuration. Security concerns here typically involve:

  • Exposed credentials or secrets in repository files
  • Malicious links in challenge files
  • GitHub Actions workflow vulnerabilities
  • Social engineering or impersonation concerns

We take all reports seriously regardless of severity.

There aren't any published security advisories