Security

Security is handled the same way across openxml-office, tauri-remote-ui,xml_rs and future projects: GitHub's native security features watch every repository, and the Azure Pipelines build adds per-language scanning and secret detection on top.

GitHub security features

Every repository has GitHub's built-in security features enabled, so vulnerabilities are surfaced and tracked automatically — from a reported CVE in a dependency all the way to leaked malware in the supply chain.

FeatureWhat it tracks
Private vulnerability reportingA private channel for anyone to responsibly disclose a vulnerability. Reports are triaged, a fix is coordinated, and a security advisory is published once resolved.
Dependency graphA complete map of the project's direct and transitive dependencies. It's the foundation the other alerts build on — nothing can be flagged unless it's known.
Dependabot alerts & updatesCross-references the dependency graph against the GitHub Advisory Database and raises an alert — with an automated fix pull request — whenever a dependency has a known vulnerability.
Malware & supply-chain alertsFlags dependencies pulled from malicious or compromised packages so a poisoned transitive dependency can't slip in unnoticed.
Secret scanningWatches the repository for accidentally committed tokens, keys and credentials and alerts before they can be abused.
Code scanningStatic analysis of the source itself to catch common security bugs and insecure patterns before they ship.

Security scanning in the pipeline

On top of GitHub's alerts, the Azure Pipelines build runs its own security stage on every pull request and merge. The scan is tailoredper language so each project's toolchain gets the checks that matter for it, and the build surfaces findings early — before a change reaches an alpha or stable channel.

See the branching model for where these stages fit in the pull-request and release flow.

Reporting a vulnerability

Please don't open a public issue for a security vulnerability. Instead, email the details privately to the maintainer atcontact@draviavemal.comso it can be triaged and fixed before any public disclosure.

A useful report usually includes: