Get started

OpenSourceOM security model

Core assumes it runs in a network you control. The database holds a copy of your inventory, IAM relationships, and findings. Protect Postgres and the API the way you protect that data.

API secret

OM_API_SECRET defaults to change-me-in-production when the variable is unset or empty. Every /v1 route except GET /v1/health requires Authorization: Bearer <secret> or X-API-Key: <secret>. That includes graph reads, findings, the rules list, blast radius, ingest, rules run, and Slack export. A missing or wrong secret is 401.

GET /v1/health does not check the secret, so probes can call it. The console HTML at / and /ui/ is also unauthenticated. The page sends the key from local storage on API calls. See Console.

Change the secret before anyone else can reach the port. Helm refuses to install until api.secret is set. The CLI never sends this header. Anyone who can open a local shell as a user with database credentials can scan and export without it.

The secret is one shared key, not a user login. Do not publish the Service to the internet. Put it on a private network or behind a gateway you operate.

Collectors

Built-in collectors call read APIs. Give them a role that cannot change infrastructure. Plugins run with your user privileges and are not sandboxed. Review plugin binaries the way you review any other code that holds cloud credentials.

POST /v1/export/slack reads the webhook from the JSON body ({"webhook":"..."}) and rejects a webhook query parameter so the URL is less likely to land in access logs. The body is still a credential. Prefer om export findings run --format slack with SLACK_WEBHOOK_URL in the environment.

Console script

The graph view loads vis-network from /ui/vis-network.min.js on the API. It is not loaded from a CDN. The API key saved in the console stays in browser local storage and is not written into the graph.

Reporting a vulnerability

Email security@opensourceom.org. Do not open a public GitHub issue for a security bug. The core repository’s SECURITY.md is the project policy.