Skip to content

Security: openbao/openbao-plugins

Security

SECURITY.md

Security Policy

Reporting a vulnerability

We take OpenBao's security and our users' trust very seriously. If you believe you have found a security issue in OpenBao, please responsibly disclose by contacting us at openbao-security@lists.openssf.org.

CVE history

Fixed OpenBao-related vulnerabilities are described in the specific release notes.

CRA stewardship

This project is supported under the Linux Foundation CRA stewardship framework. Our project CRA steward is LF Projects, LLC and its policy is available at https://www.linuxfoundation.org/security.

Security vulnerabilities should be reported through the above outlined reporting mechanism which we will coordinate with our CRA steward. For actively exploited vulnerabilities or other security matters that may require CRA escalation, please use the same security mechanism as appropriate.

Learn more about advisories related to openbao/openbao-plugins in the GitHub Advisory Database