Skip to main content
EVOKORE// SKILLS / SECURITY
Conductor-oss/conductorsecuritysha 5DE1E868FDDC

SECURITY

security policy

Security Policy

Supported Versions

VersionSupported
3.xYes
2.xSecurity patches only
< 2.0No

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue in Conductor, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Email security@conductor-oss.org with details of the vulnerability
  3. Include steps to reproduce the issue if possible
  4. Allow up to 72 hours for an initial response

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Suggested fix (if any)

Security Practices

Authentication and Authorization

  • Conductor Server supports pluggable authentication providers
  • Role-based access control (RBAC) for workflow and task management
  • API token-based authentication for task workers
  • OAuth 2.0 integration for enterprise deployments

Data Protection

  • All inter-service communication supports TLS encryption
  • Workflow input/output data can be encrypted at rest
  • Sensitive task parameters support field-level encryption
  • Audit logging for all administrative actions

Task Worker Security

  • Task workers authenticate using API tokens with configurable scopes
  • Worker-to-server communication is encrypted in transit
  • Task execution is isolated per worker instance
  • No arbitrary code execution in the orchestration layer

Disclosure Timeline

  • Day 0: Vulnerability reported
  • Day 1-3: Initial acknowledgment and triage
  • Day 7-14: Fix developed and tested
  • Day 14-30: Coordinated public disclosure