Skip to content

Security: OpenC3/cosmos

SECURITY.md

Security Policy

Supported Versions

We encourage users to be on the latest version of COSMOS and only backport security fixes for several months as users transition to the latest version.

Version Supported
5
6
7

Reporting a Vulnerability

To report a vulnerability, go to the Security and quality tab and click Report a vulnerability.

We will triage the vulnerability within 1 week and typically Accept it as a Draft. We then work on a fix and link it to the Draft advisory before submitting the CVE to Github. Github issues the CVE but we do not publicly publish it until we have released the patch into the latest version of COSMOS. We then give our customers several weeks to update to the latest version before publishing the CVE. We do monthly or better releases so from submission, to fix, to publish, can take around 2 months. Thank you for your patience and for helping keep COSMOS safe!

Learn more about advisories related to OpenC3/cosmos in the GitHub Advisory Database