Skip to content

Security: ICO-cloud/oppscc-verifier

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest

Reporting a Vulnerability

If you find a security vulnerability in the DPP-CQ Verifier, please report it:

Please include:

  • Affected version
  • Steps to reproduce
  • Impact assessment

We will acknowledge receipt within 48 hours and work to resolve the issue promptly.

Security Considerations

The verifier handles NFC tag data and QR code payloads. When contributing:

  • Never trust client-supplied data without validation
  • Use secure HTTPS for all API communications
  • Follow OWASP guidelines for web applications

There aren't any published security advisories