Skip to content

Security: damoahdominic/occ

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Send a report to security@openclaw.ai with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact

We will acknowledge your report within 48 hours and keep you updated as we work on a fix.

Scope

In scope Out of scope
OCC editor (this repo) Third-party VS Code extensions
OpenClaw extension Upstream VS Code / Void vulnerabilities
OCC website Attacks requiring physical access

Disclosure policy

We follow coordinated disclosure. Please give us a reasonable amount of time to fix an issue before making it public.

There aren’t any published security advisories