OpenTrust is a security tool — we take vulnerabilities seriously.
If you discover a security issue, do not open a public issue. Instead, send details to security@opentrust.dev (or open a GitHub Security Advisory via the "Report a vulnerability" link on the repo).
Please include:
- Description of the issue
- Steps to reproduce
- Affected versions
- Any proposed fix
- SDK code in
packages/core - React package in
packages/react - Build scripts and CI/CD
Out of scope: demo websites, example apps, and documentation.