|
| 1 | +# Security at Omarchy |
| 2 | + |
| 3 | +## Report a vulnerability |
| 4 | + |
| 5 | +If you believe you’ve found a security vulnerability in Omarchy, please tell the [Omarchy Security Team](https://omarchy.org/teams/#security) privately so we have an opportunity to investigate and fix it before it is made public. |
| 6 | + |
| 7 | +[security@omarchy.org](mailto:security@omarchy.org?subject=Security%20report) |
| 8 | + |
| 9 | +Please don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved. |
| 10 | + |
| 11 | +## What is a vulnerability? |
| 12 | + |
| 13 | +We consider a bug a security vulnerability when it can be exploited to cross a meaningful security boundary: an untrusted or lower-privileged party gains access, permissions, or control they didn’t already have. |
| 14 | + |
| 15 | +Code that could be more robust but does not cross a security boundary is an improvement rather than a security vulnerability. We may still merge a proposed fix and credit the reporter in our release notes. |
| 16 | + |
| 17 | +Eligibility for our [security credits](https://omarchy.org/security/credits/) page depends on whether a report identifies a confirmed security vulnerability, not on its severity. |
| 18 | + |
| 19 | +## What to include |
| 20 | + |
| 21 | +Give us enough information to understand and reproduce the issue: |
| 22 | + |
| 23 | +- The affected component and Omarchy version. |
| 24 | +- An explanation of what an attacker can do before and after exploitation. |
| 25 | +- Steps to reproduce the issue and any proof of concept. |
| 26 | +- Your preferred contact details for follow-up. |
| 27 | + |
| 28 | +## Responsible disclosure |
| 29 | + |
| 30 | +Please act in good faith while investigating and reporting vulnerabilities: |
| 31 | + |
| 32 | +- Only test systems and accounts you own or have explicit permission to test. |
| 33 | +- Avoid privacy violations, disruption, data destruction, and service degradation. |
| 34 | +- Don’t exploit a vulnerability beyond what is needed to demonstrate it. |
| 35 | +- Give us a reasonable opportunity to investigate and address the issue before publishing details. |
| 36 | + |
| 37 | +We’ll review your report and keep you informed as we’re able while we work toward a resolution. |
| 38 | + |
| 39 | +## Credits |
| 40 | + |
| 41 | +Researchers who privately report a confirmed security vulnerability and give us the chance to ship a fix are thanked on the [security credits](https://omarchy.org/security/credits/) page. Accepted improvements that don’t cross a security boundary may still be credited in our release notes. |
| 42 | + |
| 43 | +Credits link to each reporter’s X profile and show their avatar. For duplicate reports, only the first reporter is eligible for credit. |
| 44 | + |
| 45 | +## Regular bugs and support |
| 46 | + |
| 47 | +For anything that isn’t a security vulnerability, please use the [Omarchy issue tracker](https://github.com/omacom/omarchy/issues). |
0 commit comments