Only the latest version of the OMSS specification is supported.
Once the project reaches a stable release, a proper Long Term Support (LTS) matrix will be published here.
The OMSS team takes security seriously. We appreciate your effort to responsibly disclose vulnerabilities.
Please do NOT open a public GitHub issue for security vulnerabilities.
To report a vulnerability, please use one of the following methods:
- GitHub Security Advisories: Report a vulnerability privately via GitHub's private reporting feature.
Please include as much of the following information as possible:
- Type of vulnerability (e.g., injection, privilege escalation, information disclosure)
- Full paths of the affected source file(s)
- Location of the affected code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the vulnerability and how an attacker might exploit it
We will acknowledge receipt of your report within 72 hours and aim to provide an initial assessment within 10 business days.
We will keep you informed of our progress and notify you when a fix is released. We kindly ask that you refrain from disclosing the vulnerability publicly until a fix has been released.
We thank all security researchers who have responsibly disclosed vulnerabilities to us. Acknowledged contributors will be listed here upon their consent.