OpenTag is pre-alpha and does not currently publish supported production releases. Security reports are still welcome because early disclosure helps us fix unsafe foundations before they become stable interfaces.
Do not open a public issue or disclose vulnerability details in discussions, pull requests, or chat.
Use GitHub Private Vulnerability Reporting whenever
possible. If that channel is unavailable, email security@first-tree.ai with:
- the affected commit or version;
- reproduction steps or a proof of concept;
- the expected security impact; and
- any suggested mitigation.
Maintainers will acknowledge the report, investigate it privately, coordinate a fix, and agree on disclosure timing with the reporter. Please allow time for remediation before publishing details.