Nextcloud Native documentation

Repository documentation

Security policy

Private vulnerability reporting and the security boundaries of this early developer preview.

1 minute read · sourced from SECURITY.md

Security policy

Nextcloud Native handles app passwords, private files, messages, contacts, and other sensitive account data. Please do not report vulnerabilities in a public issue.

Reporting a vulnerability

Report vulnerabilities privately through GitHub private vulnerability reporting. If that channel is unavailable, contact the Obiente maintainers privately before sharing technical details.

Include:

  • the affected commit or release;
  • the platform and Nextcloud server/app versions;
  • the security impact and required preconditions;
  • minimal reproduction steps using redacted or synthetic data.

Do not include live credentials, share tokens, private URLs, message contents, or personal files. We will acknowledge a complete report as soon as practical, coordinate a fix, and credit reporters who want attribution.

Supported versions

The project is currently pre-release. Security fixes target the latest default branch until versioned releases begin.