Security Policy ๐
March 9, 2026 ยท View on GitHub
OpenCove takes the security of our users and their code very seriously.
Supported Versions
| Version | Supported | Notes |
|---|---|---|
0.1.x | โ Yes | Current Alpha |
< 0.1.0 | โ No | Prototype releases |
Reporting a Vulnerability
We strongly encourage you to report potential security vulnerabilities to our team.
๐ Please DO NOT
- Open a public GitHub Issue for a security vulnerability.
- Disclose the vulnerability publicly before we have had a chance to address it.
โ Please DO
- Send a private report via GitHub Security Advisories (if enabled) or email deadwavewave@gmail.com directly.
- Include a Proof of Concept (PoC) or detailed reproduction steps.
- Describe the impact of the vulnerability.
Response Timeline
We commit to the following response timeline:
- Acknowledgement: Within 72 hours.
- Assessment: We will confirm the issue and determine its severity.
- Fix: We will work to patch the vulnerability as quickly as possible.
- Disclosure: We will coordinate public disclosure with you.
Secrets & Data
If a security report involves leaked keys/tokens:
- Rotate any compromised credentials immediately.
- Redact sensitive information from screenshots or logs before sharing.
Thank you for helping keep OpenCove secure. ๐ก๏ธ