Only security issues found in released code, that is, has a release tag are considered.
The ONVIF team and community take security bugs in media signing framework seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions. To report a security issue, please send an email to security@onvif.org.
The ONVIF team will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Note that the repository implements the ONVIF Media Signing Specification. Nevertheless, both security issues found in the repository code as well as the specification are handled through security@onvif.org.