ossf/oss-vulnerability-guide

A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.

142

stars

176

commits

HTML

primary language

Aug 19, 2026

updated

oss-vulnerability-guide.openssf.org/

README

Guide to coordinated vulnerability disclosure for open source software projects

GitHub Super-Linter

This repository is a set of resources and reference materials to help open source projects perform coordinated vulnerability disclosure (CVD).

This repository contains:

Getting Started

If you are new to coordinated vulnerability disclosure, it is recommended you start with the Guide. While it is dense, you will want to be familiar with this information and the concepts presented before you need to address a vulnerability report.

If you are familiar with coordinated vulnerability disclosure, you can get a refresher by skipping to the Response Process section of the Guide, or go straight to the Runbook.

Feedback

We welcome feedback from OSS project maintainers and security researchers on this guide. Opening a GitHub Issue is the best way to send feedback (see CONTRIBUTING.md for directions on submitting PRs).

Contributors

david-a-wheeler

72 commits

SecurityCRob

38 commits

annebdh

38 commits

ran-dall

4 commits

ossf/oss-vulnerability-guide

A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.

142

stars

176

commits

HTML

primary language

Aug 19, 2026

updated

oss-vulnerability-guide.openssf.org/

README

Guide to coordinated vulnerability disclosure for open source software projects

GitHub Super-Linter

This repository is a set of resources and reference materials to help open source projects perform coordinated vulnerability disclosure (CVD).

This repository contains:

Getting Started

If you are new to coordinated vulnerability disclosure, it is recommended you start with the Guide. While it is dense, you will want to be familiar with this information and the concepts presented before you need to address a vulnerability report.

If you are familiar with coordinated vulnerability disclosure, you can get a refresher by skipping to the Response Process section of the Guide, or go straight to the Runbook.

Feedback

We welcome feedback from OSS project maintainers and security researchers on this guide. Opening a GitHub Issue is the best way to send feedback (see CONTRIBUTING.md for directions on submitting PRs).

Contributors

david-a-wheeler

72 commits

SecurityCRob

38 commits

annebdh

38 commits

ran-dall

4 commits

Languages

HTML

57.7%

SCSS

39.3%

Ruby

3.0%