Private contact: security@openexits.org
This is the organisation-wide default. The commons repository has its own
SECURITY.md which takes
precedence there, because it covers an additional and more urgent kind of report.
The reference validator, the CI gates and the contribution panel are ordinary software. Of particular interest:
- anything letting a contributor write outside
sites/orroutes/through the publisher, - anything bypassing the CI gates or the provenance stamping,
- anything exposing the panel's accounts, unpublished media, or terms-acceptance records.
Email security@openexits.org with enough detail to reproduce, and please allow a reasonable window to fix before disclosing publicly. There is no bounty — this is a volunteer, non-commercial project — but you will be credited if you want to be.
If a site is published that should not be, that is more urgent than any software bug, and it is time-critical: content in a public repository stays reachable after deletion. Email security@openexits.org, name the file or commit only, and do not describe the site in any public channel. Full policy: SENSITIVE-EXITS.md.
You need not be a contributor or a maintainer to report this. If you are a local jumper who thinks a site should not be listed, that is exactly the report we want.
OpenExits is stewarded by its founder and a small group of maintainers while the non-profit association that will take it over is being formed. There is no 24/7 rota. Put "sensitive exit" in the subject line for those reports — they are triaged ahead of everything else.