Skip to content

Security: OSSAfrica/Governance

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

Open Source & Security Africa (OSSAfrica) takes security seriously. We appreciate your efforts to responsibly disclose security vulnerabilities.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing: security@ossafrica.org

Include the following information:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any suggested fixes or mitigations

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 7 days
  • Status Updates: Every 14 days until resolution

Scope

This security policy covers:

  • OSSAfrica governance repositories
  • Community infrastructure and platforms
  • Official OSSAfrica tools and applications
  • Community Discord server security issues

Security Standards

OSSAfrica follows these security practices:

Repository Security

  • All repositories require signed commits for maintainers
  • Branch protection rules enforce code review requirements
  • Dependency scanning enabled on all repositories
  • Regular security audits of governance documents

Community Security

  • Code of Conduct enforcement
  • Moderation guidelines for community spaces
  • Privacy protection for community members
  • Secure communication channels

Infrastructure Security

  • Multi-factor authentication required for all maintainers
  • Regular access reviews and permission audits
  • Encrypted communication for sensitive discussions
  • Secure backup and recovery procedures

Supported Versions

Version Supported
Latest
Previous
Older

Security Contact

For urgent security matters, contact the Core Team through:

  • Email: security@ossafrica.org
  • Discord: Direct message to Core Team members
  • OpenSSF BEAR Working Group escalation for critical issues

Attribution

We will acknowledge security researchers who responsibly disclose vulnerabilities in our security advisories, unless they prefer to remain anonymous.

There aren’t any published security advisories