Security Policy
June 15, 2026 ยท View on GitHub
Reporting a Vulnerability
If you find a security vulnerability in OpenUsage, please report it responsibly. Do not open a public issue.
Preferred: GitHub Security Advisories
- Go to the Security Advisories page
- Click "Report a vulnerability"
- Fill in the details
This keeps the report private until a fix is released.
Alternative: Email
Send details to rob@robinebers.com with the subject line "OpenUsage Security Report".
What to Include
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Impact assessment (what can an attacker do?)
Response Timeline
- Acknowledgment within 48 hours
- Assessment and plan within 7 days
- Fix released as soon as practical, depending on severity
Scope
The following are in scope:
- The OpenUsage desktop application
- The built-in providers (credential handling, API calls)
- The local HTTP API
- Build and release infrastructure
The following are out of scope:
- Third-party provider APIs (report to the provider directly)
- Social engineering attacks
- Denial of service attacks
Supported Versions
Only the latest release is supported with security updates.