cat SECURITY.md
If you believe you’ve found a security vulnerability in Omarchy, please tell the Omarchy Security Team privately so we have an opportunity to investigate and fix it before it is made public.
Please don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved.
cat what-is-a-vulnerability.md
We consider a bug a security vulnerability when it can be exploited to cross a meaningful security boundary: an untrusted or lower-privileged party gains access, permissions, or control they didn’t already have.
Code that could be more robust but does not cross a security boundary is an improvement rather than a security vulnerability. We may still merge a proposed fix and credit the reporter in our release notes.
Eligibility for our security credits page depends on whether a report identifies a confirmed security vulnerability, not on its severity.
cat what-to-include.md
Give us enough information to understand and reproduce the issue:
cat responsible-disclosure.md
Please act in good faith while investigating and reporting vulnerabilities:
We’ll review your report and keep you informed as we’re able while we work toward a resolution.
cat credits.md
Researchers who privately report a confirmed security vulnerability and give us the chance to ship a fix are thanked on the security credits page. Accepted improvements that don’t cross a security boundary may still be credited in our release notes.
Credits link to each reporter’s X profile and show their avatar. For duplicate reports, only the first reporter is eligible for credit.
For anything that isn’t a security vulnerability, please use the Omarchy issue tracker.