If you discover a security issue in any ODS framework or spec, please do not open a public GitHub issue. Instead, use GitHub’s private vulnerability reporting to file a private advisory.
We’ll acknowledge receipt within a week and keep you updated on the fix.
ODS is pre-1.0. Fixes land on main; there is no LTS or back-porting
commitment yet. Once stable releases begin (tracked in
CHANGELOG.md when it exists), this section will list the
versions that receive security fixes.
In scope for reports:
Out of scope: