Skip to content

Security: msgmate-io/open-chat-go

SECURITY.md

Security Policy

Project status

Open-Chat is beta software. The project has not been fully security-audited, and we do not guarantee security updates for any specific version or release. You use this software at your own risk. See NOTICE for the licensing and component status.

Reporting a vulnerability

Please report security issues or hardening proposals by email to:

tim+security@timschupp.de

Please do not open a public GitHub issue for a suspected vulnerability.

Due to the volume of reports and the significant share of LLM-assisted contributions in this project, we cannot review every report immediately. Each report is handled individually and may take time to triage.

Bounties

There is no official bug-bounty program. However, very high impact and directly exploitable vulnerabilities may still be rewarded on a per-report basis, at our sole discretion.

Disclosure and remediation

Where a report can be verified, we intend to publish an audit log and document the resolution of the vulnerability. There is no formal disclosure process established yet; we plan to define one in the future.

Supported versions

Because the project is in beta, no version receives guaranteed security updates.

Version Security updates
Any / beta None guaranteed

Scope

This policy applies to the source code in this repository. Private (proprietary) components and integrations described in NOTICE are excluded from the public grant and are handled separately.

There aren't any published security advisories