Skip to content

Report a vulnerability

Do not open a public issue for a suspected vulnerability.

Use GitHub private vulnerability reporting.

  • a concise description;
  • the affected commit, tag, or package version;
  • minimal reproduction steps or a proof of concept;
  • expected and observed behavior;
  • potential impact;
  • any suggested mitigation.

Remove unrelated personal data and credentials. Do not attach a complete .odinn directory, browser profile, OAuth store, gateway token, audit signing key, or unsanitized backup.

The project makes a best-effort attempt to acknowledge reports within seven calendar days. During an active investigation, the goal is to provide a status update at least every 14 days, including when there is no material change.

Disclosure timing is coordinated after impact and remediation are understood. Where appropriate, the target coordinated-disclosure window is up to 90 days from the initial report. Severity, active exploitation, remediation availability, or downstream coordination may change that target.

Use the repository’s bug report form for non-security defects. Before reporting, collect the safe diagnostics described in Diagnostics.

The maintained source policy is SECURITY.md.