Skip to content

Security: technophylax/ocpa

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Supported Versions

  • Main branch; tagged releases.

Expectations

  • Do not test against production deployments you don’t own.
  • Avoid exploiting beyond proof of concept; share logs/traces if safe.

Out of Scope

  • Social engineering, physical attacks, or issues requiring privileged local access outside OCPA.

Pre-release checks

  • Run a secret scan (gitleaks/trufflehog) on history before public releases; actions are wired to allow scans on demand.

There aren’t any published security advisories