The OpenINF team takes the security of OpenINF and the applications created with it seriously. This page describes how to report any vulnerabilities you may find and lists best practices to minimize the risk of introducing a vulnerability.
In the rare event that you find a vulnerability in the OpenINF SDK itself, email us.
-
Keep current with the latest OpenINF SDK releases. We regularly update the OpenINF SDK, and these updates may fix security defects discovered in earlier versions. Check the OpenINF SDK changelog for security-related updates.
-
Keep your application’s dependencies up to date. Make sure you upgrade your package dependencies to keep the dependencies up to date. Avoid pinning to specific versions for your dependencies. If you do, make sure you check periodically to see if your dependencies have had security updates and update the pin accordingly.