Please do not report security vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting feature instead:
https://github.com/yuhp/opencode-models-discovery/security/advisories/new
Please include as much of the following information as possible:
- A description of the vulnerability and its potential impact
- The affected version or commit
- Reproduction steps or a proof of concept
- Any relevant logs, configuration, or error messages
- A suggested mitigation, if available
Security issues may include credential or API key exposure, unexpected external network requests, unauthorized provider configuration changes, sensitive data in persisted caches, or release and GitHub Actions supply-chain problems.
Please avoid including real credentials or other sensitive data in reports.
Only the latest release is actively supported with security fixes.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
We will acknowledge a valid report as soon as practical, assess its impact, and coordinate a fix and disclosure timeline with the reporter.