Coordinated disclosure

Report sensitive findings privately

If a finding could be exploitable, email security@osspublicaudit.com or use the repository's private security advisory form. Do not open a public issue, pull request, discussion, or project nomination.

What to include

  • Affected repository, release, and exact commit
  • Minimal reproduction steps and impact
  • Required configuration, hardware, or threat assumptions
  • Whether the upstream project has already been contacted

Publication

Potentially exploitable details remain private during triage and coordinated remediation. Public records distinguish suspected, reproduced, fixed, dismissed, and disclosure-withheld findings.