The OpenSourceOM team takes security seriously. We appreciate responsible disclosure.
Report security issues privately. Do not open a public GitHub issue.
Email security@opensourceom.org with:
- Description of the issue
- Steps to reproduce
- Impact assessment (if known)
- Your preferred contact (optional)
We aim to acknowledge reports within 72 hours.
In scope:
- Public repositories in the OpenSourceOM organization and their official releases
- Official deployment manifests
- The project website when an issue affects user safety (for example, XSS on opensourceom.org)
Out of scope:
- Third-party dependencies (report them upstream; we track CVEs that affect our projects)
- Social engineering, physical attacks, and denial of service
We support good-faith research. Do not access data that is not yours, exfiltrate data, or disrupt services.
We prefer coordinated disclosure. We will work with you on timing and credit unless you prefer anonymity.