Report a vulnerability
If you believe you’ve found a security vulnerability in Omarchy, please tell the Omarchy Security Team privately so we have an opportunity to investigate and fix it before it is made public.
security@omarchy.orgPlease don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved.
What to include
Give us enough information to understand and reproduce the issue:
- The affected component and Omarchy version.
- Steps to reproduce the vulnerability.
- The impact and any proof of concept you have.
- Your preferred contact details for follow-up.
Responsible disclosure
Please act in good faith while investigating and reporting vulnerabilities:
- Only test systems and accounts you own or have explicit permission to test.
- Avoid privacy violations, disruption, data destruction, and service degradation.
- Don’t exploit a vulnerability beyond what is needed to demonstrate it.
- Give us a reasonable opportunity to investigate and address the issue before publishing details.
We’ll review your report and keep you informed as we’re able while we work toward a resolution.
Regular bugs and support
For anything that isn’t a security vulnerability, please use the Omarchy issue tracker.