The Oxia maintainers take security seriously and appreciate your efforts to responsibly disclose your findings.
Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
Instead, report them privately through GitHub's private vulnerability reporting form. Use the same form for vulnerabilities in any other repository of the oxia-db organization (client libraries, Helm charts, etc.) and mention the affected repository in the report.
Please include in your report:
- A description of the vulnerability and of its potential impact
- The affected component and version(s)
- Steps to reproduce the issue, or a proof of concept
- Any known mitigation or suggested fix
The maintainers will acknowledge your report within 3 business days and will provide an initial assessment, with an estimated timeline for a fix, within 10 business days.
We will keep you informed of the progress toward a fix and may ask you for additional information.
Oxia follows a coordinated disclosure process. When a vulnerability is confirmed, the maintainers will:
- Develop and test a fix privately
- Request a CVE identifier, if appropriate
- Release a patched version
- Publish a security advisory, crediting the reporter unless they prefer to remain anonymous
We ask you to keep the details of the vulnerability private until the advisory is published.
Security fixes are released as a patch release of the latest minor version of Oxia. They may also be
backported to an earlier minor version that still has an active release-X.Y branch, at the discretion
of the maintainers.
We recommend running the latest release.
The Oxia maintainers act as the security response team of the project and handle the reports according to this policy. See GOVERNANCE.md for more details.