generated: '2026-08-29' method: searched source: https://github.com/AcademySoftwareFoundation/openexr/blob/main/SECURITY.md note: >- The automated security-program probe (probe-security-programs.py) returned vdp=none because ASWF serves no /.well-known/security.txt on any host and runs no bug-bounty platform page. It does publish a real, detailed coordinated-disclosure policy — per project, in SECURITY.md in each repository — with named contacts, an acknowledgement SLA, and published CVE criteria. That is a vulnerability disclosure program; it simply is not discoverable at the path the probe checks. program: type: coordinated-disclosure bug_bounty: false platform: null security_txt: false security_txt_probe: - url: https://www.aswf.io/.well-known/security.txt status: 404 - url: https://openexr.com/.well-known/security.txt status: 404 - url: https://www.opencue.io/.well-known/security.txt status: 404 policies: - project: OpenEXR url: https://github.com/AcademySoftwareFoundation/openexr/blob/main/SECURITY.md intake: - channel: github-security-advisory url: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/new - channel: email address: security@openexr.com acknowledgement_sla: 48 hours patch_target: critical vulnerabilities patched within 14 days where possible cve_policy_published: true cve_criteria: requests_cve_for: - >- Memory-safety violations (out-of-bounds write, use-after-free, heap corruption) reachable on mainstream 64-bit architectures through the public library API, confirmed in an unsanitized build, affecting library code so that every downstream consumer inherits it. does_not_request_cve_for: - 32-bit-only bugs (fixed, but no CVE — downstream packagers build 64-bit) - Developer-tool-only crashes (exrmetrics, exrcheck) - Flaws rooted in a bundled dependency such as OpenJPH — the upstream project owns the CVE - project: OpenCue url: https://github.com/AcademySoftwareFoundation/OpenCue/blob/master/SECURITY.md intake: - channel: email address: opencue-tsc-private@lists.aswf.io note: Only TSC members and ASWF project management can read this list. acknowledgement_sla: response within 14 days outstanding_issues: none listed addressed_issues: none listed foundation_guidance: best_practices_guide: https://github.com/AcademySoftwareFoundation/tac/blob/main/project_best_practices_guides/security.md badge_guidance: https://github.com/AcademySoftwareFoundation/tac/blob/main/process/best_practices_badge.md note: >- ASWF's TAC publishes a security best-practices guide and an OpenSSF Best Practices badge process that hosted projects are expected to follow. Per-project badge status is asserted in each project's own README and is not re-asserted here.