This repository holds the OpenVoiceOS Technical Manual — documentation only, no runnable service and no user data. If you found a documentation bug that gives unsafe advice (for example a config example that would expose the message bus to the network), please open a regular issue or pull request against this repo.
For an actual security vulnerability in an OpenVoiceOS component (ovos-core,
ovos-messagebus, ovos-PHAL, a specific skill, etc.), do not open a public
issue. Use GitHub's private vulnerability reporting on the affected repository
instead:
- Go to the repository on GitHub (for example
https://github.com/OpenVoiceOS/ovos-core). - Open the Security tab.
- Choose Report a vulnerability to open a private advisory visible only to maintainers.
If a repository does not have private reporting enabled, contact the maintainers through the community channels linked from the Open Voice OS website instead of filing a public issue.
See Privacy & Security for the network- and trust-model overview of a default OVOS install.