Security
Advisories
Every security advisory we publish, newest first. Each states what is affected, what the impact is, what to do about it, and who found it.
-
OGMA-2026-001 — Write-scoped repository token present inside a third-party build VM
The release build pipeline, for every release up to and including v0.5.0. No installed OgmaProtect software is affected.
Reporting something
Email security@ogmaprotect.com. We acknowledge within three working days. What happens after that — including what we do and do not commit to — is on the security page.
Only the latest release is supported, and the remedy for any advisory is to upgrade to it. There are no maintenance branches. Current release is v0.5.5; it is on the download page, signed.