Skip to content

Security: DioCrafts/OxiCloud

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of OxiCloud are currently supported with security updates:

Version Supported
Latest

Reporting a Vulnerability

The OxiCloud team takes security issues seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.

To report a security vulnerability, please follow these steps:

  1. DO NOT disclose the vulnerability publicly (e.g., in GitHub issues)
  2. Email details of the vulnerability to the project maintainers
  3. Include as much information as possible, such as:
    • A clear description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact
    • Suggested fixes if available

What to Expect

After submitting a vulnerability report, you can expect the following:

  1. Acknowledgment: The team will acknowledge receipt of your report within 3 business days
  2. Assessment: We'll evaluate the vulnerability and determine its impact
  3. Plan: We'll develop a plan to address the vulnerability
  4. Fix & Release: Once fixed, we'll release an update
  5. Recognition: With your permission, we'll acknowledge your contribution in the release notes

Security Best Practices for OxiCloud Users

  • Keep your OxiCloud installation updated to the latest version
  • Use strong, unique passwords for all user accounts
  • Configure proper file permissions
  • Regularly back up your data
  • Consider running OxiCloud behind a reverse proxy with HTTPS
  • Implement IP restrictions where appropriate

Thank you for helping keep OxiCloud and its users secure!

There aren’t any published security advisories