odoo / owl

OWL: A web framework for structured, dynamic and maintainable applications
https://odoo.github.io/owl/
Other
1.14k stars 343 forks source link

Request for Security Policy and Reporting Vulnerabilities #1644

Open tulik opened 1 day ago

tulik commented 1 day ago

Hi team,

I’m looking for information on the security policy for this project and the correct process for reporting any possible security issues or vulnerabilities. Where should we report potentially sensitive security vulnerabilities?

Thank you!

ged-odoo commented 9 hours ago

You can either contact me directly (ged at odoo dot com), or contact the Oodo security team (https://www.odoo.com/security-report). Note that many security tools report vulnerabilities in our package.json dependency list. However, those vulnerabilities do not apply as we actually only use these for development, and the only javascript that is packaged is the actual owl source code.