Security
Security and responsible disclosure
OpenDir welcomes good-faith security research and handles vulnerability reports privately.
Report a vulnerability
Please use a private GitHub security advisory. Do not publish exploit details, credentials, personal information, or sensitive submission data in a public issue.
What to include
- A clear description of the issue and its potential impact.
- The affected page, endpoint, or component.
- Minimal reproduction steps or a proof of concept that does not expose user data.
- Any practical remediation ideas you have identified.
Good-faith testing
Please avoid privacy violations, service disruption, data destruction, automated high-volume traffic, social engineering, or accessing information that does not belong to you. Stop testing and report privately if sensitive data becomes visible.
Our approach
OpenDir separates public submissions and directory access from protected moderation actions, keeps secrets outside the source repository, and records review decisions for accountability. Security controls and operational procedures are reviewed as the service evolves.
Third-party projects
OpenDir lists independently operated software. Vulnerabilities in a listed project should be reported to that project’s owner. Directory approval is not a security certification or endorsement.
Effective 9 August 2026 · OpenDir Registry 0.2.0