Skip to content
Coordinated disclosure

Report a vulnerability

We welcome and reward good-faith security research. If you've found a vulnerability in OSDF, this page tells you how to reach us and what to expect.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us a reasonable opportunity to remediate before public disclosure.

security@osdfsystems.com
Process

What to expect

Day 0

Report received

Acknowledgement within one business day.

Day 1–3

Triage

We validate, assign severity, and confirm scope.

Day ≤90

Remediation

We develop, test, and ship a fix; you stay informed.

Day Fix + 7

Disclosure

Coordinated, signed advisory with credit if desired.

In scope
  • OSDF reference core, CLI, and SDKs
  • Verification, Ledger, and Enterprise APIs
  • Web Editor and hosted services
  • Transparency log and witness infrastructure
Out of scope
  • Volumetric DoS and rate-limit testing
  • Social engineering of staff or customers
  • Findings requiring a fully compromised endpoint
  • Reports from automated scanners without impact

Recognition

Valid reports are credited in our signed advisories and security hall of fame, with researcher consent. For high-impact findings we offer rewards commensurate with severity and quality.

PGP public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEXel0… (truncated - fetch the full key at /.well-known/security.txt)=ABCD-----END PGP PUBLIC KEY BLOCK-----