Only the latest release of OKF4net receives security fixes.
Please do not open a public issue for security problems.
Report vulnerabilities privately via GitHub private vulnerability reporting (Security tab → "Report a vulnerability"). If that is not an option, email julien.chable@gmail.com with a description, reproduction steps, and impact assessment.
You can expect an acknowledgement within a few days. Please allow a reasonable window for a fix to be released before any public disclosure.
OKF4net parses untrusted markdown/YAML input by design (okf validate,
Bundle.Load). Crashes, unbounded resource consumption, or path-traversal
issues triggered by crafted bundle content are all in scope.