The projects OneHill stewards are meant to run on people's own machines with their own data. We take vulnerabilities seriously.
Do not open a public issue for a security problem.
Report privately by either route:
- Preferred: open a private advisory through GitHub, on the affected repository, under Security > Report a vulnerability.
- Email: dev@onehill.org. If you want to encrypt, ask for our key first.
Please include:
- The affected project and version or commit.
- A description of the issue and its impact.
- Steps to reproduce, a proof of concept, or affected code paths.
- Any suggested fix or mitigation.
OneHill is a young foundation and this process is still being set up, so please bear with us.
- We will acknowledge your report as soon as we can, and aim to do so within a few working days.
- We will assess it, keep you updated on progress, and let you know when a fix ships.
- With your consent, we are glad to credit you when we disclose.
Thank you for reporting responsibly. Please give us a reasonable chance to fix the issue before any public disclosure.
This policy covers the repositories in this organisation. Vulnerabilities in third-party dependencies should be reported upstream; tell us too if a OneHill project is affected.