Skip to content

Security: OpenExits/specification

Security

SECURITY.md

Security policy

Private contact: security@openexits.org

This is the organisation-wide default. The commons repository has its own SECURITY.md which takes precedence there, because it covers an additional and more urgent kind of report.

Reporting a vulnerability

The reference validator, the CI gates and the contribution panel are ordinary software. Of particular interest:

  • anything letting a contributor write outside sites/ or routes/ through the publisher,
  • anything bypassing the CI gates or the provenance stamping,
  • anything exposing the panel's accounts, unpublished media, or terms-acceptance records.

Email security@openexits.org with enough detail to reproduce, and please allow a reasonable window to fix before disclosing publicly. There is no bounty — this is a volunteer, non-commercial project — but you will be credited if you want to be.

Reporting a sensitive exit site

If a site is published that should not be, that is more urgent than any software bug, and it is time-critical: content in a public repository stays reachable after deletion. Email security@openexits.org, name the file or commit only, and do not describe the site in any public channel. Full policy: SENSITIVE-EXITS.md.

You need not be a contributor or a maintainer to report this. If you are a local jumper who thinks a site should not be listed, that is exactly the report we want.

Response expectations

OpenExits is stewarded by its founder and a small group of maintainers while the non-profit association that will take it over is being formed. There is no 24/7 rota. Put "sensitive exit" in the subject line for those reports — they are triaged ahead of everything else.

There aren't any published security advisories