generated: '2026-07-27' method: searched probe: true source: https://github.com/GreenButtonAlliance/OpenESPI-GreenButton-Java/blob/main/openespi-common/SECURITY.md description: >- Green Button Alliance publishes no /.well-known/security.txt and no responsible-disclosure page on greenbuttonalliance.org (both probed, 404). It does publish a real, specific security policy in its reference-implementation repository, with a dedicated security mailbox and a stated response SLA. That repository policy is the provider's actual disclosure channel and is recorded here verbatim in substance. policy: - https://github.com/GreenButtonAlliance/OpenESPI-GreenButton-Java/blob/main/openespi-common/SECURITY.md contact: - security@greenbuttonalliance.org reporting_instructions: do_not: Do NOT create a public GitHub issue for security vulnerabilities. channel: Email security@greenbuttonalliance.org include: - Description of the vulnerability - Steps to reproduce - Potential impact assessment - Any suggested fixes response_commitments: - Acknowledgment within 48 hours - Initial assessment within 1 week - Regular updates on progress - Credit in security advisories (if desired) supported_versions: - {version: 1.4.x, supported: true, note: Current Spring Boot 3.5 migration} - {version: 1.3.x, supported: false, note: Legacy version, archived} - {version: '< 1.3', supported: false, note: Legacy versions, archived} security_controls_published: - GitHub Actions CI/CD - automated security scanning on all PRs and commits - OWASP Dependency Check - automated vulnerability scanning of dependencies - Dependabot - automated security updates for dependencies - Trivy - container and filesystem vulnerability scanning - TruffleHog - secrets detection in code - SonarCloud - static code analysis for security issues disclosed_security_debt: note: >- Unusually candid for a standards body - GBA documents its own outstanding risk in the same policy file. items: - Legacy spring-security-oauth2 2.5.2 scheduled for replacement - Direct Xerces XML dependency scheduled for removal - Some entity classes have compilation issues during the Spring Boot 3.5 migration bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false security_txt: published: false probed: - {url: 'https://www.greenbuttonalliance.org/.well-known/security.txt', status: 404} evidence: - source: https://github.com/GreenButtonAlliance/OpenESPI-GreenButton-Java/blob/main/openespi-common/SECURITY.md kind: SECURITY.md fetched: '2026-07-27' http_status: 200 - source: https://www.greenbuttonalliance.org/.well-known/security.txt kind: security.txt fetched: '2026-07-27' http_status: 404 - source: https://www.greenbuttonalliance.org/legal kind: terms-and-conditions fetched: '2026-07-27' http_status: 200 note: >- GBA's legal page carries an "Email Security" section alongside Terms & Conditions, Permitted Uses, Trademark Usage, Hosting and Analytics. Consistent with the probed DMARC policy of p=reject on greenbuttonalliance.org.