Skip to content

Security: osgi/org.osgi.util.function

Security

SECURITY.md

Security Policy

The OSGi Specification Project follows the Eclipse Foundation Vulnerability Reporting Policy.

Reporting a Vulnerability

Please do not report security issues through public GitHub issues.

  • Preferred: use GitHub's private vulnerability reporting — "Report a vulnerability" under the Security tab of the affected repository.
  • Alternatively, email the Eclipse Foundation Security Team at security@eclipse-foundation.org.

Please include the affected repository, the artifact and version, a description of the issue and, where possible, steps to reproduce.

Disclosure

Reports are handled confidentially in coordination with the Eclipse Foundation Security Team; you should receive an initial response within a few business days. Fixes are developed privately and published together with an advisory. In line with the Eclipse Foundation policy, vulnerability details may be publicly disclosed at the latest three months after the initial report, even if no fix is available by then.

Supported Versions

Security fixes are provided for the most recent released version of each specification artifact.

There aren't any published security advisories