Skip to content

Security: congodevelopersclub/openpaycongo

Security

SECURITY.md

Security reporting

Do not publish vulnerabilities, raw SMS, credentials, tokens, private keys, usable enrollment artifacts, or personal payment data in public issues, pull requests, logs, screenshots, or CI output.

Private reporting route

A private security-reporting route is not yet published. Until maintainers publish and verify one, do not submit sensitive vulnerability details to this repository. Use a verified official maintainer channel outside the repository and share only the minimum information needed to establish contact.

What maintainers must decide

Maintainers must publish the accountable security/release role, backup escalation path, acknowledgement target, disclosure coordination process, and emergency rebuild or revocation authority. They must also approve the vulnerability and dependency exception policy before automation can accept any exception.

Safe public reports

Non-sensitive reports may describe affected version, high-level impact, reproduction using synthetic data, and whether a workaround exists. Do not include exploit payloads or operational topology details that make exploitation easier.

There aren't any published security advisories