This policy applies to all repositories in the OpenInsightHQ organization.
| Version | Supported |
|---|---|
latest main |
✅ |
| older releases | ❌ |
We take security seriously. If you discover a security vulnerability, please do not open a public issue.
Report it privately via one of these channels:
- GitHub private vulnerability reporting — open the affected repository → Security tab → Report a vulnerability
- Email — contact@o-insight.com
Please include:
- Type of issue (e.g. authentication bypass, injection, data exposure)
- Affected repository and component
- Step-by-step reproduction or proof of concept
- Potential impact
We will acknowledge reports within 72 hours and keep you informed about remediation progress. Coordinated disclosure is appreciated.
- Vulnerabilities in third-party dependencies should be reported upstream, but feel free to notify us as well so we can update pinned versions.
- Self-hosted misconfiguration (exposed ports, unchanged default secrets) is generally out of scope unless it stems from project defaults.