Every repository in the OxyHQ organisation is in scope, and every published @oxy.so/* package with it. We provide security updates for the latest release of each; older versions may not receive patches.
Archived repositories are out of scope. They are marked as archived on their repository page.
If you discover a security vulnerability in any Oxy product, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Use either channel:
- Report a vulnerability on the Security tab of the affected repository. Private vulnerability reporting is enabled on every public repository, and this is the channel we prefer, since the report stays attached to the code.
- Email security@oxy.so.
Either way, include:
- A description of the vulnerability
- Steps to reproduce
- The affected product and version
- Any potential impact assessment
We will acknowledge your report within 48 hours and provide an initial assessment within 5 business days.
- We follow coordinated disclosure practices.
- We will work with you to understand and address the issue before any public disclosure.
- We credit reporters in our security advisories (unless you prefer to remain anonymous).
This policy applies to all repositories in the OxyHQ GitHub organization.