Skip to content

Security: hubab1/OpenASO

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest released version of OpenASO.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities privately using GitHub Security Advisories.

Include:

  • A description of the vulnerability and its impact
  • The affected OpenASO and macOS versions
  • Reproduction steps or a proof of concept
  • Any suggested remediation

OpenASO handles App Store Connect credentials, Apple Ads sessions, API keys, and local application data. Never include active credentials, private keys, passwords, cookies, tokens, or personal data in a report. Use redacted values or test accounts.

Response and Disclosure

We aim to acknowledge reports within five business days. Please allow time for a fix before publicly disclosing the vulnerability. We will coordinate disclosure and credit with the reporter where appropriate.

There aren't any published security advisories