ORÓMA is an offline-first adaptive edge intelligence architecture. It may run on local Linux edge devices, use local web interfaces, systemd services, SQLite databases, camera/audio components, PTZ control, and model/runtime integrations.
Security reports are welcome, but please do not disclose exploitable details publicly before they can be reviewed.
Security feedback is relevant for:
- Local Flask/UI routes and API endpoints.
- Authentication and token handling.
- Systemd service configuration.
- File permissions and runtime paths.
- SQLite/DBWriter access patterns.
- Import/export boundaries.
- Camera/audio/PTZ safety boundaries.
- Unsafe defaults in public configuration examples.
- Documentation that could lead users to expose secrets or private data.
Please do not include the following in GitHub/Codeberg issues or pull requests:
.env,.env.systemd, tokens, passwords, API keys, SSH keys, TLS keys, certificates.- SQLite databases such as
oroma.db,stats.db,knowledge.db. *.db-wal,*.db-shm, backups, archives, or live runtime state.- Logs containing hostnames, IPs, personal data, tokens, camera paths, or private environment values.
- Camera snapshots, audio recordings, sensor dumps, or personal data.
- Exploit payloads that can be copied and used against live systems.
Preferred reporting path:
- Open a minimal public issue saying that you have a security concern, without exploit details.
- Provide a safe, high-level description of the affected component.
- Wait for maintainer guidance on how to share details privately.
If a private contact address is later published in the repository metadata, use that channel for sensitive details.
A useful report should include:
- Affected file, route, service, or component.
- Expected security boundary.
- Observed behavior.
- Minimal reproduction steps using dummy data.
- Impact assessment.
- Suggested mitigation, if known.
This is a small independent research project. Response times may vary. Security issues that can expose secrets, permit unintended remote access, bypass local UI protection, or cause unsafe PTZ/device behavior are treated as high priority.
Public examples should assume:
- Local-first deployment.
- No public exposure of the UI without explicit hardening.
- No publishing of DBs, logs, runtime state, or model weights.
- No default trust in uploaded/imported files.
- No silent fallback to unsafe write paths.