opsdash-app/SECURITY.md
blade34242 afa9ea60e8
Some checks failed
Nextcloud Server Tests / version-consistency (push) Successful in 44s
Nextcloud Server Tests / matrix-config (push) Successful in 33s
Nextcloud Server Tests / Nextcloud stable30 / PHP 8.2 (stable30, 8.2) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable31 / PHP 8.2 (stable31, 8.2) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable31 / PHP 8.3 (stable31, 8.3) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable32 / PHP 8.2 (stable32, 8.2) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable32 / PHP 8.3 (stable32, 8.3) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable33 / PHP 8.2 (stable33, 8.2) (push) Has been cancelled
Nextcloud Server Tests / Nextcloud stable33 / PHP 8.3 (stable33, 8.3) (push) Has been cancelled
Prepare 0.8.2 release
2026-07-09 10:49:57 +07:00

1.1 KiB

Security Policy

Project Note

Opsdash is built and maintained as a hobby project. I put real effort into security hardening, validation, and review, but this is still best-effort maintenance. If you spot something suspicious, please report it. Helpful reports make the app safer for everyone.

Supported Versions

We currently support the 0.8.x line (Nextcloud 30-34).

How to Report

  • Sensitive/security-critical issue: please use the private security contact below.
  • Non-sensitive security concern or hardening suggestion: opening a normal issue is welcome.
  • Alternate private contact: opsdash-security@gellert-innovation.dev (PGP optional).

Please include:

  • clear reproduction steps
  • expected vs actual behavior
  • Nextcloud version
  • Opsdash version
  • relevant logs/screenshots (with secrets removed)

Response Expectations

  1. Acknowledgement target: within 3 business days.
  2. Triage update target: usually within 7 days.
  3. Fix and release notes: tracked in CHANGELOG.md and the release notes workflow.

Please avoid public disclosure of exploitable vulnerabilities until a fix is available.