Repository documentation
Security policy
Private vulnerability reporting and the security boundaries of this early developer preview.
Security policy
Nextcloud Native handles app passwords, private files, messages, contacts, and other sensitive account data. Please do not report vulnerabilities in a public issue.
Reporting a vulnerability
Report vulnerabilities privately through GitHub private vulnerability reporting. If that channel is unavailable, contact the Obiente maintainers privately before sharing technical details.
Include:
- the affected commit or release;
- the platform and Nextcloud server/app versions;
- the security impact and required preconditions;
- minimal reproduction steps using redacted or synthetic data.
Do not include live credentials, share tokens, private URLs, message contents, or personal files. We will acknowledge a complete report as soon as practical, coordinate a fix, and credit reporters who want attribution.
Supported versions
The project is currently pre-release. Security fixes target the latest default branch until versioned releases begin.