Until 1.0, only the most recent tagged release receives security fixes. Operators should follow the upgrade notes and avoid unversioned images.
Do not open a public issue. Use GitHub's Security → Report a vulnerability private reporting form for this repository. Include the affected version, prerequisites, reproduction steps, impact, and any proposed remediation. Remove personal data and live credentials from evidence.
Maintainers aim to acknowledge a report within 3 business days, provide an initial assessment within 10 business days, and coordinate disclosure after a fix is available. Timelines may change with severity and complexity. Good-faith research that avoids privacy violations, service disruption, and data destruction is welcome.
Organelle stores workforce data. Operators are responsible for access policy, TLS, network controls, encrypted storage and backups, retention, monitoring, provider security, and compliance obligations. Rotate any credential suspected of exposure before sending a report.