Security

Security policy foundation

A dedicated security contact will be published before the first public release.

Responsible disclosure

Guidelines will be published with the first public repositories.

Security issue reporting

Reporting channels will be published before public release.

Supported versions

Supported versions will be listed after public releases exist.

Security updates

Security update notifications are planned for future self-hosted products.

Dependency management

Projects are intended to use repeatable builds and documented dependency policies.

Data ownership

Self-hosted product data is intended to remain under the administrator's control.

Telemetry policy

Telemetry is planned to be opt-in and disabled by default.