Skip to content

Security: opengeospatial/teamengine

Security

SECURITY.md

Security Policy

Thank you for helping improve the security and trustworthiness of Open Geospatial Consortium (OGC) resources.

OGC welcomes responsible disclosure of security vulnerabilities affecting OGC-operated systems, repositories, software, standards-related resources, registries, Building Blocks, APIs, and other digital services.

OGC welcomes reports concerning not only software vulnerabilities, but also cybersecurity weaknesses affecting standards, registries, schemas, Building Blocks, APIs, provenance, interoperability, and other trusted digital artifacts maintained by OGC.

Reporting a Security Vulnerability

Please report suspected security vulnerabilities by email to:

security@ogc.org

Please include as much information as possible, including:

  • A description of the vulnerability
  • The affected system, repository, or service
  • URLs, repository names, or identifiers
  • Steps required to reproduce the issue
  • Screenshots or logs (if appropriate)
  • Potential impact
  • Suggested mitigations (if known)

Encrypted submissions may be supported upon request.


Scope

Examples of resources covered by this policy include:

  • OGC GitHub organizations
  • OGC GitLab
  • OGC websites
  • OGC Definitions Server
  • OGC Registries
  • OGC Building Blocks
  • Compliance resources
  • Public APIs
  • Reference implementations
  • Public software developed by OGC
  • Security considerations within OGC standards and implementation guidance

Out of Scope

The following activities are generally outside the scope of this policy:

  • Social engineering
  • Physical attacks
  • Denial-of-service testing
  • Spam
  • Vulnerabilities in third-party services not operated by OGC
  • Automated scanning that significantly impacts service availability

Coordinated Disclosure

OGC follows a Coordinated Vulnerability Disclosure process.

Please allow OGC a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure.

OGC will work collaboratively with researchers throughout the disclosure process.


Safe Harbor

OGC supports good-faith security research.

OGC will not pursue legal action against individuals who:

  • act in good faith,
  • avoid privacy violations,
  • avoid service disruption,
  • avoid data destruction,
  • promptly report discovered vulnerabilities, and
  • comply with this policy.

Response Targets

OGC aims to:

Activity Target
Acknowledge report Within 3 business days
Initial assessment Within 10 business days
Status updates Approximately every 30 days
Resolution As appropriate for the vulnerability

These targets are goals rather than guarantees.


Recognition

OGC appreciates responsible disclosure.

Researchers who responsibly disclose vulnerabilities may be publicly acknowledged with their consent.

There aren't any published security advisories