generated: '2026-08-06' method: searched probe: true source: https://github.com/ogen-go/ogen/blob/main/SECURITY.md policy: - https://github.com/ogen-go/ogen/blob/main/SECURITY.md - https://github.com/ogen-go/ogen/security/policy reporting: channel: github-private-vulnerability-reporting url: https://github.com/ogen-go/ogen/security/advisories/new description: >- ogen directs vulnerability reports to GitHub's private security advisory flow under the repository's Security tab. No email address, PGP key, bug bounty program or security.txt is published. contact: [] bug_bounty: none security_txt: none policy_text: >- Use GitHub Security Reporting to report security vulnerabilities under the "Security" section. supply_chain: - control: dependabot evidence: .github/dependabot.yml; dependency-bump commits appear in every recent release. - control: distroless-base-image evidence: >- Dockerfile pins gcr.io/distroless/static-debian13 and documents dropping the "base" variant to remove libssl3 after CVE-2026-31789 surfaced in a scan. - control: static-analysis evidence: .golangci.yml with gosec annotations (#nosec) in cmd/ogen/main.go. - control: coverage-reporting evidence: .codecov.yaml; codecov badge in README. evidence: - source: https://github.com/ogen-go/ogen/blob/main/SECURITY.md kind: security-policy http_status: 200 - source: https://raw.githubusercontent.com/ogen-go/ogen/main/Dockerfile kind: supply-chain http_status: 200 - source: https://ogen.dev/.well-known/security.txt kind: security.txt http_status: 404 x-evidence: fetched: '2026-08-06'