▄▄▄
 ▄█████▄    ▄███████████▄    ▄███████   ▄███████   ▄███████   ▄█   █▄    ▄█   █▄
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   ███  ███   ███  ███   ███
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   █▀   ███   ███  ███   ███
███   ███  ███   ███   ███ ▄███▄▄▄███ ▄███▄▄▄██▀  ███       ▄███▄▄▄███▄ ███▄▄▄███
███   ███  ███   ███   ███ ▀███▀▀▀███ ▀███▀▀▀▀    ███      ▀▀███▀▀▀███  ▀▀▀▀▀▀███
███   ███  ███   ███   ███  ███   ███ ██████████  ███   █▄   ███   ███  ▄██   ███
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   ███  ███   ███  ███   ███
 ▀█████▀    ▀█   ███   █▀   ███   █▀   ███   ███  ███████▀   ███   █▀    ▀█████▀
                                       ███   █▀

Security at Omarchy

Report a vulnerability

If you believe you’ve found a security vulnerability in Omarchy, please tell the Omarchy Security Team privately so we have an opportunity to investigate and fix it before it is made public.

security@omarchy.org

Please don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved.

What to include

Give us enough information to understand and reproduce the issue:

  • The affected component and Omarchy version.
  • Steps to reproduce the vulnerability.
  • The impact and any proof of concept you have.
  • Your preferred contact details for follow-up.

Responsible disclosure

Please act in good faith while investigating and reporting vulnerabilities:

  • Only test systems and accounts you own or have explicit permission to test.
  • Avoid privacy violations, disruption, data destruction, and service degradation.
  • Don’t exploit a vulnerability beyond what is needed to demonstrate it.
  • Give us a reasonable opportunity to investigate and address the issue before publishing details.

We’ll review your report and keep you informed as we’re able while we work toward a resolution.

Regular bugs and support

For anything that isn’t a security vulnerability, please use the Omarchy issue tracker.