Skip to content

Security: OptimCE/billing

Security

SECURITY.md

Security Policy

Supported Versions

OptimCE does not publish tagged releases yet. Security fixes are applied to the main branch of each repository.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, use one of these channels:

  1. GitHub private vulnerability reporting (preferred): go to the Security tab of this repository and click "Report a vulnerability".
  2. Email: contact@optimce.be.

Please include as much of the following as you can:

  • The type of issue (e.g. injection, authentication bypass, privilege escalation, information disclosure)
  • The affected service, and file(s) or endpoint(s)
  • Step-by-step instructions to reproduce the issue, or a proof of concept
  • The impact you believe the issue has, and how an attacker might exploit it

What to Expect

OptimCE is maintained by a small team. We aim to acknowledge your report within a few business days, keep you informed while we investigate, and credit you in the fix (unless you prefer to remain anonymous). Please give us a reasonable amount of time to address the issue before any public disclosure.

Scope

This repository holds the OptimCE billing service, one of several repositories under the OptimCE organization. If a vulnerability affects billing specifically, report it here. If you are not sure which service is affected — or the issue spans several — reporting it here (or by email) is fine; we will route it to the right place.

There aren't any published security advisories