Pre-release. v0.1 is not out yet, so there is nothing to install and no public source to clone — the quickstart builds from a checkout.
Reporting a vulnerability
Onbe is security infrastructure. A report is a favour, and it is treated as one.
How to report
Section titled “How to report”Email znikola96@gmail.com. Do not open a public issue for a security problem.
Please include:
- The affected version or commit.
- What the issue is.
- Reproduction steps, if you have them.
What to expect
Section titled “What to expect”- Acknowledgement within 3 working days.
- An assessment and a planned fix timeline within 10 working days.
- Coordinated disclosure. We ask for 90 days before public disclosure, and will usually publish sooner once a fix is released.
In scope: the control plane, token issuance and validation, the audit ledger, and the SDKs.
Out of scope:
- Findings that require an already-compromised host.
- Issues in example configuration, which is explicitly not production hardened.
- Denial of service through unbounded request volume.
The threat model sets out what the system is and is not meant to defend against, and is the right place to check before writing a report.
Supported versions
Section titled “Supported versions”During 0.x, only the latest release receives security fixes.
OnbePre-release. v0.1 is not out yet.
© 2026 Onbe