If you discover a security vulnerability in OGO, please report it
responsibly by opening a GitHub issue
with the label security.
For sensitive reports, email aknochow@redhat.com directly.
OGO manages AI agent sandboxes on OpenShift. Security-relevant areas include:
- Auth-bridge (OAuth token handling, JWT minting)
- Sandbox pod security (SCC, network policies)
- TLS certificate management
- Credential injection (provider Secrets)
Only the latest version on main is supported. OGO is alpha software.