Skip to content

Security: OpenInsightHQ/openinsight

Security

SECURITY.md

Security Policy

This policy applies to all repositories in the OpenInsightHQ organization.

Supported Versions

Version Supported
latest main
older releases

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please do not open a public issue.

Report it privately via one of these channels:

  • GitHub private vulnerability reporting — open the affected repository → Security tab → Report a vulnerability
  • Emailcontact@o-insight.com

Please include:

  • Type of issue (e.g. authentication bypass, injection, data exposure)
  • Affected repository and component
  • Step-by-step reproduction or proof of concept
  • Potential impact

We will acknowledge reports within 72 hours and keep you informed about remediation progress. Coordinated disclosure is appreciated.

Scope

  • Vulnerabilities in third-party dependencies should be reported upstream, but feel free to notify us as well so we can update pinned versions.
  • Self-hosted misconfiguration (exposed ports, unchanged default secrets) is generally out of scope unless it stems from project defaults.

There aren't any published security advisories