Security fixes are prioritized for the default branch and currently supported releases of each OpenHealthOS repository.
Please report vulnerabilities privately through the repository's GitHub Security Advisories flow. Do not open a public issue for a suspected vulnerability.
Include:
- a clear description of the issue and affected component;
- reproducible steps or a proof of concept;
- potential impact and any relevant configuration details; and
- a safe way to contact you for follow-up.
Do not include patient data, production credentials, secrets, or other sensitive information in a report.
We will acknowledge reports, investigate the impact, and coordinate a fix and disclosure timeline with the reporter when possible. Please allow time for triage and remediation before public disclosure.