Repository documentation
Security policy
Private vulnerability reporting and the security boundaries of this early developer preview.
1 minute read · sourced from SECURITY.mdSecurity policy
Nextcloud Native handles app passwords, private files, messages, contacts, and other sensitive account data. Please do not report vulnerabilities in a public issue.
Reporting a vulnerability
Report vulnerabilities privately through GitHub private vulnerability reporting. If that channel is unavailable, contact the Obiente maintainers privately before sharing technical details.
Include:
- the affected commit or release;
- the platform and Nextcloud server/app versions;
- the security impact and required preconditions;
- minimal reproduction steps using redacted or synthetic data.
Do not include live credentials, share tokens, private URLs, message contents, or personal files. We will acknowledge a complete report as soon as practical, coordinate a fix, and credit reporters who want attribution.
Supported versions
The project is currently pre-release. Security fixes target the latest default branch until versioned releases begin.