Public repositories.
All current Ozark Security Labs public repositories are in scope unless a repository publishes a narrower policy.
View organizationUse this route for suspected vulnerabilities in Ozark Security Labs public projects. Send sensitive details only to the security inbox.
Report privately, include evidence, and give maintainers time to respond before public disclosure.
Email security@ozarksecuritylabs.com for suspected vulnerabilities in public Ozark Security Labs repositories. Please do not open a public issue for an unpatched vulnerability.
Security reporting and vulnerability disclosure belong in the same workflow: private intake, bounded testing, and coordinated remediation.
All current Ozark Security Labs public repositories are in scope unless a repository publishes a narrower policy.
View organizationAvoid destructive testing, persistence, data exfiltration, social engineering, service disruption, and attacks against third-party systems.
Email securityWe review reports, ask for clarification when needed, work toward a fix when impact is confirmed, and coordinate public disclosure timing.
View security.txt