▄▄▄
 ▄█████▄    ▄███████████▄    ▄███████   ▄███████   ▄███████   ▄█   █▄    ▄█   █▄
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   ███  ███   ███  ███   ███
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   █▀   ███   ███  ███   ███
███   ███  ███   ███   ███ ▄███▄▄▄███ ▄███▄▄▄██▀  ███       ▄███▄▄▄███▄ ███▄▄▄███
███   ███  ███   ███   ███ ▀███▀▀▀███ ▀███▀▀▀▀    ███      ▀▀███▀▀▀███  ▀▀▀▀▀▀███
███   ███  ███   ███   ███  ███   ███ ██████████  ███   █▄   ███   ███  ▄██   ███
███   ███  ███   ███   ███  ███   ███  ███   ███  ███   ███  ███   ███  ███   ███
 ▀█████▀    ▀█   ███   █▀   ███   █▀   ███   ███  ███████▀   ███   █▀    ▀█████▀
                                       ███   █▀

Security at Omarchy

Report a vulnerability

If you believe you’ve found a security vulnerability in Omarchy, please tell the Omarchy Security Team privately so we have an opportunity to investigate and fix it before it is made public.

[email protected]

Please don’t report potential vulnerabilities publicly in GitHub Issues, Discord, or social media before they’ve been resolved.

What to include

Give us enough information to understand and reproduce the issue:

  • The affected component and Omarchy version.
  • Steps to reproduce the vulnerability.
  • The impact and any proof of concept you have.
  • Your preferred contact details for follow-up.

Responsible disclosure

Please act in good faith while investigating and reporting vulnerabilities:

  • Only test systems and accounts you own or have explicit permission to test.
  • Avoid privacy violations, disruption, data destruction, and service degradation.
  • Don’t exploit a vulnerability beyond what is needed to demonstrate it.
  • Give us a reasonable opportunity to investigate and address the issue before publishing details.

We’ll review your report and keep you informed as we’re able while we work toward a resolution.

Credits

Everyone who has reported a security issue privately and given us the chance to ship a fix is thanked on the security credits page.

Regular bugs and support

For anything that isn’t a security vulnerability, please use the Omarchy issue tracker.