Sitelet https://github.com/devhttps/omarchy/commit/7aceb388e76ef8b18eab710c959279df37aeea2d
Skip to content

Commit 7aceb38

Browse files
authored
Merge pull request omacom#9226 from omacom/security/add-security-policy
Add security policy
2 parents e689946 + f8d7fae commit 7aceb38

1 file changed

Lines changed: 47 additions & 0 deletions

File tree

‎.github/SECURITY.md‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
# Security at Omarchy
2+
3+
## Report a vulnerability
4+
5+
If you believe you’ve found a security vulnerability in Omarchy, please tell the [Omarchy Security Team](https://omarchy.org/teams/#security) privately so we have an opportunity to investigate and fix it before it is made public.
6+
7+
[security@omarchy.org](mailto:security@omarchy.org?subject=Security%20report)
8+
9+
Please don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved.
10+
11+
## What is a vulnerability?
12+
13+
We consider a bug a security vulnerability when it can be exploited to cross a meaningful security boundary: an untrusted or lower-privileged party gains access, permissions, or control they didn’t already have.
14+
15+
Code that could be more robust but does not cross a security boundary is an improvement rather than a security vulnerability. We may still merge a proposed fix and credit the reporter in our release notes.
16+
17+
Eligibility for our [security credits](https://omarchy.org/security/credits/) page depends on whether a report identifies a confirmed security vulnerability, not on its severity.
18+
19+
## What to include
20+
21+
Give us enough information to understand and reproduce the issue:
22+
23+
- The affected component and Omarchy version.
24+
- An explanation of what an attacker can do before and after exploitation.
25+
- Steps to reproduce the issue and any proof of concept.
26+
- Your preferred contact details for follow-up.
27+
28+
## Responsible disclosure
29+
30+
Please act in good faith while investigating and reporting vulnerabilities:
31+
32+
- Only test systems and accounts you own or have explicit permission to test.
33+
- Avoid privacy violations, disruption, data destruction, and service degradation.
34+
- Don’t exploit a vulnerability beyond what is needed to demonstrate it.
35+
- Give us a reasonable opportunity to investigate and address the issue before publishing details.
36+
37+
We’ll review your report and keep you informed as we’re able while we work toward a resolution.
38+
39+
## Credits
40+
41+
Researchers who privately report a confirmed security vulnerability and give us the chance to ship a fix are thanked on the [security credits](https://omarchy.org/security/credits/) page. Accepted improvements that don’t cross a security boundary may still be credited in our release notes.
42+
43+
Credits link to each reporter’s X profile and show their avatar. For duplicate reports, only the first reporter is eligible for credit.
44+
45+
## Regular bugs and support
46+
47+
For anything that isn’t a security vulnerability, please use the [Omarchy issue tracker](https://github.com/omacom/omarchy/issues).

0 commit comments

Comments
 (0)