Coordinated disclosure
Report sensitive findings privately
If a finding could be exploitable, email security@osspublicaudit.com or use the repository's private security advisory form. Do not open a public issue, pull request, discussion, or project nomination.
What to include
- Affected repository, release, and exact commit
- Minimal reproduction steps and impact
- Required configuration, hardware, or threat assumptions
- Whether the upstream project has already been contacted
Publication
Potentially exploitable details remain private during triage and coordinated remediation. Public records distinguish suspected, reproduced, fixed, dismissed, and disclosure-withheld findings.