OpenSourceOM security model
Core assumes it runs in a network you control. The database holds a copy of your inventory, IAM relationships, and findings. Protect Postgres and the API the way you protect that data.
API secret
OM_API_SECRET defaults to change-me-in-production when the variable
is unset or empty. Every /v1 route except GET /v1/health requires
Authorization: Bearer <secret> or X-API-Key: <secret>.
That includes graph reads, findings, the rules list, blast radius, ingest, rules run, and
Slack export. A missing or wrong secret is 401.
GET /v1/health does not check the secret, so probes can call it. The console
HTML at / and /ui/ is also unauthenticated. The page sends the key
from local storage on API calls. See Console.
Change the secret before anyone else can reach the port. Helm refuses to install until
api.secret is set. The CLI never sends this header. Anyone who can open a local
shell as a user with database credentials can scan and export without it.
The secret is one shared key, not a user login. Do not publish the Service to the internet. Put it on a private network or behind a gateway you operate.
Collectors
Built-in collectors call read APIs. Give them a role that cannot change infrastructure. Plugins run with your user privileges and are not sandboxed. Review plugin binaries the way you review any other code that holds cloud credentials.
POST /v1/export/slack reads the webhook from the JSON body
({"webhook":"..."}) and rejects a webhook query parameter so
the URL is less likely to land in access logs. The body is still a credential. Prefer
om export findings run --format slack with SLACK_WEBHOOK_URL in
the environment.
Console script
The graph view loads vis-network from /ui/vis-network.min.js on the API. It is
not loaded from a CDN. The API key saved in the console stays in browser local storage and
is not written into the graph.
Reporting a vulnerability
Email security@opensourceom.org. Do not open a public GitHub issue for a security bug. The core repository’s SECURITY.md is the project policy.
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.