Skip to content

Security: OneHillAI/.github

Security

SECURITY.md

Security Policy

The projects OneHill stewards are meant to run on people's own machines with their own data. We take vulnerabilities seriously.

Reporting a vulnerability

Do not open a public issue for a security problem.

Report privately by either route:

  • Preferred: open a private advisory through GitHub, on the affected repository, under Security > Report a vulnerability.
  • Email: dev@onehill.org. If you want to encrypt, ask for our key first.

Please include:

  • The affected project and version or commit.
  • A description of the issue and its impact.
  • Steps to reproduce, a proof of concept, or affected code paths.
  • Any suggested fix or mitigation.

What to expect

OneHill is a young foundation and this process is still being set up, so please bear with us.

  • We will acknowledge your report as soon as we can, and aim to do so within a few working days.
  • We will assess it, keep you updated on progress, and let you know when a fix ships.
  • With your consent, we are glad to credit you when we disclose.

Thank you for reporting responsibly. Please give us a reasonable chance to fix the issue before any public disclosure.

Scope

This policy covers the repositories in this organisation. Vulnerabilities in third-party dependencies should be reported upstream; tell us too if a OneHill project is affected.

There aren't any published security advisories