Skip to content

Security: Obiente/nc-native

Security

SECURITY.md

Security policy

Nextcloud Native handles app passwords, private files, messages, contacts, and other sensitive account data. Please do not report vulnerabilities in a public issue.

Reporting a vulnerability

Report vulnerabilities privately through GitHub private vulnerability reporting. If that channel is unavailable, contact the Obiente maintainers privately before sharing technical details.

Include:

  • the affected commit or release;
  • the platform and Nextcloud server/app versions;
  • the security impact and required preconditions;
  • minimal reproduction steps using redacted or synthetic data.

Do not include live credentials, share tokens, private URLs, message contents, or personal files. We will acknowledge a complete report as soon as practical, coordinate a fix, and credit reporters who want attribution.

Supported versions

Last reviewed: 2026-08-20. Release and security-support status may have changed. Check the latest releases and their notes for current published limitations.

The project is pre-release at this review date. Reports are assessed against the latest default branch; no older release line is declared supported here.

There aren't any published security advisories