Apache OpenDAL Reqsign follows the Apache Software Foundation security process. Please report suspected vulnerabilities privately to private@opendal.apache.org. If you are unsure where to send the report, use the ASF Security Team address, security@apache.org. Do not open public GitHub issues or pull requests for security reports.
When reporting, include:
reqsign use, Apache OpenDAL integration, or another embedding application;The security boundary, in-scope findings, out-of-scope deployment issues, and triage guidance for this repository are documented in THREAT_MODEL.md.
Apache OpenDAL is Reqsign‘s primary integration for custom key signing and cloud-provider authentication, but Reqsign can also be embedded directly by other applications. OpenDAL-specific storage behavior, operator authorization, path policy, and storage-service trust boundaries are covered by OpenDAL’s own security documentation.