Security fixes are applied to the latest released version. Upgrade to the latest GitHub release before reporting behavior that might already be fixed.
Use GitHub's private vulnerability reporting for this repository. Please do not open a public issue for suspected vulnerabilities.
Include:
- the affected OpsLens version and operating system;
- the smallest reproducible description;
- the expected security impact;
- whether credentials, model requests, indexed evidence, telemetry access, or tenant boundaries are involved; and
- any suggested mitigation.
Do not include live credentials, customer logs, private source code, database files, or other sensitive evidence. Use synthetic examples and coordinate a secure transfer only if maintainers request additional material.
OpsLens is currently a local-first single-operator tool. Shared storage, multi-tenant hosting, and a hosted control plane are not part of the supported release boundary.