We take the security of OpenAdapt seriously. If you believe you have found a security vulnerability in this repository, please report it privately — do not open a public issue, discussion, or pull request that describes it.
Preferred: use GitHub's private vulnerability reporting. Go to the repository's Security tab and click Report a vulnerability. This opens a private advisory visible only to the maintainers.
Alternative: email hello@openadapt.ai with the details.
Please include, where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce (a proof-of-concept if you have one)
- Affected version(s), commit, endpoint, or configuration
- Any suggested remediation
- We will acknowledge your report within 5 business days.
- We will provide an estimated timeline for a fix and keep you updated on progress.
- We will credit reporters who wish to be acknowledged once a fix has shipped.
- Please give us a reasonable opportunity to remediate before any public disclosure.
Security fixes are applied to the latest released version on the main branch.
Thank you for helping keep OpenAdapt and its users safe.