If you discover a security vulnerability in OpenDiff, please report it responsibly. Do not open a public GitHub issue.
Email juliuswallblom@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions or components
- Potential impact
You should receive a response within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.
This policy covers the OpenDiff repository and its packages:
apps/bff- API serverapps/app- Console dashboardapps/site- Marketing siteapps/review-agent- AI code review agentpackages/shared- Shared librariespackages/components- UI components
- Issues in third-party dependencies (report these upstream)
- Social engineering attacks
- Denial of service attacks