Current state
Omoikane Labs is establishing its private reporting channel, coordination process, and release authorization gates. Until those exist, sensitive reports must not be sent through public GitHub issues or the website repository.
Before research becomes public
- The affected maintainer or vendor has authorized publication, or the documented coordination period has ended.
- A public fix or mitigation exists where appropriate.
- Active exploitation and dual-use distribution risk have been reviewed.
- Redistribution rights for code, logs, datasets, and third-party materials have been checked.
- Two people approve the publication manifest, and a non-author reviews the website pull request.
This page will be replaced by a complete coordinated-disclosure policy before Omoikane Labs accepts reports.