If you discover a security vulnerability in OpenWatch:
- Do not open a public issue or discuss it publicly
- Email security@openwatch.com with details
- We will acknowledge your report within 3 business days and coordinate a fix
- Responsible disclosure is appreciated and recognized
We support the latest major release of OpenWatch. Please update to the latest version before reporting vulnerabilities.
- Keep dependencies up to date
- Use strong, unique passwords for all accounts
- Never share API keys or secrets
Thanks to all security researchers and users who help keep OpenWatch secure.