Skip to content

Security: openbimrs/ifc

SECURITY.md

Security policy

Supported versions

No stable GitHub release has been published yet. Security fixes target the current main branch and will be included in the next applicable release.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting for this repository:

https://github.com/openbimrs/ifc/security/advisories/new

Include, where possible:

  • the affected commit or package version;
  • the smallest safe reproduction;
  • the security impact and expected trust boundary;
  • whether malformed IFC, STEP, XML, archive, or schema input is involved;
  • any suggested mitigation.

Do not upload confidential building models or standards material that you do not have the right to share. A reduced synthetic fixture is preferred.

The maintainers will keep the report private while it is assessed and will coordinate disclosure after a fix or mitigation is available. No response-time SLA is currently promised.

The same private form is also the project's confidential conduct-reporting channel. Prefix non-security reports with [Conduct] and follow the Code of Conduct.

There aren't any published security advisories