Do not open a public issue for security problems. Report privately.
- Open a private advisory: GitHub → Security → Report a vulnerability
- Or email the maintainers via the repository's GitHub contact
Please include:
- The affected version / commit
- A description of the vulnerability
- Steps to reproduce (if possible)
- Impact assessment
- We acknowledge reports within 48h.
- We aim to triage within 5 business days.
- Critical issues get a fix priority over feature work.
This applies to omnigate itself. The tools it calls (systemd, QEMU, the
kernel) have their own security processes.