Security

Security and responsible disclosure

OpenDir welcomes good-faith security research and handles vulnerability reports privately.

Report a vulnerability

Please use a private GitHub security advisory. Do not publish exploit details, credentials, personal information, or sensitive submission data in a public issue.

What to include

  • A clear description of the issue and its potential impact.
  • The affected page, endpoint, or component.
  • Minimal reproduction steps or a proof of concept that does not expose user data.
  • Any practical remediation ideas you have identified.

Good-faith testing

Please avoid privacy violations, service disruption, data destruction, automated high-volume traffic, social engineering, or accessing information that does not belong to you. Stop testing and report privately if sensitive data becomes visible.

Our approach

OpenDir separates public submissions and directory access from protected moderation actions, keeps secrets outside the source repository, and records review decisions for accountability. Security controls and operational procedures are reviewed as the service evolves.

Third-party projects

OpenDir lists independently operated software. Vulnerabilities in a listed project should be reported to that project’s owner. Directory approval is not a security certification or endorsement.

Effective 9 August 2026 · OpenDir Registry 0.2.0