The OpenSourceOM team takes security seriously. We appreciate responsible disclosure.
Email security@opensourceom.org with:
- Description of the issue
- Steps to reproduce
- Impact assessment (if known)
- Your preferred contact (optional)
We aim to acknowledge reports within 72 hours.
In scope:
- OpenSourceOM
corerepository and official releases - Official deployment manifests in this repo
- The project website if it affects user safety (e.g. XSS on opensourceom.org)
Out of scope:
- Third-party dependencies (report upstream; we will track CVEs). Dependabot opens weekly PRs. CI runs
govulncheckand CodeQL. - Social engineering, physical attacks, denial of service
We support good-faith research. Do not access data that is not yours, exfiltrate customer data, or disrupt services.
We prefer coordinated disclosure. We will work with you on timing and credit unless you prefer anonymity.