Skip to content

Security: open-wander/ramble

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release is supported with security updates.

Reporting a Vulnerability

Please report security vulnerabilities responsibly. Do not open public issues for security concerns.

Email: security@openwander.org

GitHub: Report a vulnerability

We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 7 days.

Scope

  • The Ramble web application and API
  • The rmbl CLI tool
  • Authentication and authorisation flows
  • Data exposure or injection vulnerabilities

Out of Scope

  • Denial of service attacks
  • Social engineering
  • Issues in third-party dependencies (report these upstream)

There aren’t any published security advisories