Security

Security reports are welcome for these websites, the live services, and the projects, including software that has not yet published its source.

Which path to use

  • General questions about the security design of a project: hello@oesalabs.com.
  • Ordinary bug reports with no security impact: the project's issue tracker once its repository is public, or the same general address until then.
  • Vulnerabilities, anything with security impact: security@oesalabs.com, privately, before any public disclosure.

Reporting a vulnerability

Send a description of the issue, steps to reproduce it, the affected project or site, and the impact you believe it has. Text is enough; a proof of concept helps but is not required. Please do not run disruptive testing against the live services.

What to expect

Oesa Labs is a small studio, so this is a best-effort commitment rather than a service-level agreement: reports are acknowledged as quickly as possible, normally within a few days, and you will hear what happens next. Coordinated disclosure is respected; you will not be asked to sign anything, and credit is offered where a fix ships. There is no bug bounty programme.

Scope notes

These websites are static, with no accounts, forms, or third-party analytics, which narrows their attack surface deliberately. The machine-readable security contact is published at /.well-known/security.txt.