Responsible Disclosure
Report an issue in Platform Signal
Prefer a private GitHub vulnerability report against moonseer/program-signal when available. If that channel is unavailable, open an issue titled SECURITY: without exploit details, secrets, or personal data in the public body.
Include the affected component, high-level reproduction steps, and impact. This is not a bug bounty. Good-faith reporters who avoid disruption and privacy harm will not be pursued for the report alone.
Vulnerabilities found while researching articles
- Validate privately with minimal reproduction.
- Notify the vendor or maintainer through their security contact.
- Coordinate on timing when reasonable.
- Publish only afterward, if the story is still warranted.
Public articles may describe impact classes and mitigations. They must not include working exploit details or step-by-step attack procedures.
Ordinary article errors use the corrections process. Full policy: docs/editorial/RESPONSIBLE-DISCLOSURE.md.