Security fixes are made against the latest release. Older releases do not receive backported fixes; upgrade to the latest release to pick up a security fix.
Report vulnerabilities through GitHub private security advisories on this repository: https://github.com/NavistAu/openbao-plugin-secrets-onepassword/security/advisories/new
Do not report vulnerabilities through public GitHub issues. There is no email route for vulnerability reports; use the private advisory form above so the report stays confidential until a fix is available.
Include enough detail to reproduce the issue: plugin version, OpenBao version, relevant mount configuration (with secrets redacted), and the observed behavior.
- Acknowledgment of your report within 7 days.
- Coordinated disclosure: you will get advance notice before any public advisory is published.
- Credit in the advisory, unless you prefer otherwise.