Skip to content

Security: localcompose/locom

Security

SECURITY.md

Security Policy for LocalCompose

Reporting a Vulnerability

LocalCompose uses GitHub Security Advisories for confidential security reporting. To report a security vulnerability:

  1. Navigate to our Security Advisories page: Submit Security Advisory
  2. Only the security team can see and triage your submission.
  3. Please do not report vulnerabilities in public issues, pull requests, or discussions.
  4. Tip for community reporters: Keep the link provided after submission to review or update your report. If you lose the link or cannot access your original submission, submitting a new advisory with updated information is welcome. The security team values updates from community reporters to help triage and resolve vulnerabilities.

How and When to Report

  • Only submit issues that represent genuine security vulnerabilities.
  • Provide as much detail as possible to reproduce the issue safely.
  • The security team will review, triage, and coordinate fixes privately.
  • Once resolved, advisories may be disclosed publicly with fixes.

There aren't any published security advisories