Skip to content

Security: LeonGaoHaining/opencowork

Security

SECURITY.md

Security Policy

We take security issues seriously and appreciate responsible disclosure.

Reporting a Vulnerability

Please use GitHub Security Advisories instead of opening a public issue for sensitive findings.

What to Include

Please include:

  • affected version(s),
  • severity assessment,
  • reproduction steps,
  • expected vs actual behavior,
  • and an optional remediation suggestion.

Response Targets

Severity First Response Target Fix Window
Critical 24 hours 7 days
High 3 days 14 days
Medium 7 days 30 days
Low 14 days 90 days

Scope Notes

OpenCowork is often deployed in trusted single-user desktop environments. That deployment model changes risk priorities for some classes of issues, but it does not eliminate the need to report meaningful vulnerabilities.

Security Release Process

Security fixes are released in patch versions whenever possible.

Example:

  • v0.10.9 -> v0.10.10

Thanks

We appreciate responsible disclosure and will credit reporters when appropriate.

There aren’t any published security advisories