Skip to content

Security: nasa/fprime

SECURITY.md

Security Policy

The F´ team secures our code base using a combination of code review, dependency review, and static analysis performed during automated pull request verification. We welcome general bug reports and vulnerability reports from the larger community.

Reporting a Vulnerability

For general defects, please submit a Bug Report.

To report a vulnerability for F´ please use the vulnerability report form.

If you are using AI tools to assist with your reporting, we require that you disclose this in your report. Please review the AI policy for guidelines on disclosure and best practices.

Static Analysis Checks

The GitHub Actions workflows are available to the public. To review the results, fork the repository and run the workflows.

These checks are run on each pull request submitted to F´.

General Support

For additional support, please open a Discussion.

Learn more about advisories related to nasa/fprime in the GitHub Advisory Database