If you believe you found a security issue in OpenMontage, do not open a public issue or pull request.
Please use GitHub's private vulnerability reporting for this repository so the report stays confidential while it is triaged and fixed.
Include as much of the following as you can:
- A clear description of the issue and its impact
- Affected versions, branches, or pipeline names
- Reproduction steps or proof of concept
- Any logs, screenshots, or sample inputs that help explain the issue
Do not include secrets, tokens, passwords, or other sensitive credentials in the report unless they are absolutely required to demonstrate the problem.
We treat the following as security-relevant:
- Secret leakage or unsafe handling of credentials
- Dependency or supply-chain vulnerabilities
- Authentication, authorization, or privilege-escalation issues
- Unsafe handling of user-provided media, prompts, or metadata
- Sandbox escapes, arbitrary code execution, or data exfiltration
- Exposure of private project artifacts, API keys, or generated assets
The following are usually not security issues unless they create a concrete exploit path:
- Feature requests or general bug reports
- Missing hardening that does not expose an attack surface
- Third-party service outages unrelated to OpenMontage
- Misconfiguration in a user-managed environment without evidence of a product flaw
When we receive a valid report, we aim to:
- Acknowledge receipt promptly
- Triage severity and scope
- Prepare and test a fix
- Coordinate disclosure after a fix is available
If the issue is actively exploited or broadly impactful, we will prioritize containment and user notification as part of the response.
OpenMontage is an agent-driven video production system that may interact with:
- Local files and generated project assets
- Third-party APIs for media, narration, and video generation
- User-supplied prompts, transcripts, media, and metadata
Security assumptions:
- Privileged repository contributors are trusted to protect their credentials and enable MFA
- External providers are trusted only for the scope of the API calls we make to them
- Generated artifacts may contain sensitive data if the source inputs do
If you are unsure whether something is in scope, report it anyway and let us triage it.
The repository should be maintained with a few basic controls in place:
- Privileged contributors should enable MFA
- Protected branches should require review and status checks before merge
- Dependency updates should be automated where possible
- Code scanning should run in CI so issues are caught early