Coordinated disclosure
Report a vulnerability
We welcome and reward good-faith security research. If you've found a vulnerability in OSDF, this page tells you how to reach us and what to expect.
Safe harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and data destruction, and give us a reasonable opportunity to remediate before public disclosure.
security@osdfsystems.com
Process
What to expect
Day 0
Report received
Acknowledgement within one business day.
Day 1–3
Triage
We validate, assign severity, and confirm scope.
Day ≤90
Remediation
We develop, test, and ship a fix; you stay informed.
Day Fix + 7
Disclosure
Coordinated, signed advisory with credit if desired.
In scope
- OSDF reference core, CLI, and SDKs
- Verification, Ledger, and Enterprise APIs
- Web Editor and hosted services
- Transparency log and witness infrastructure
Out of scope
- Volumetric DoS and rate-limit testing
- Social engineering of staff or customers
- Findings requiring a fully compromised endpoint
- Reports from automated scanners without impact
Recognition
Valid reports are credited in our signed advisories and security hall of fame, with researcher consent. For high-impact findings we offer rewards commensurate with severity and quality.
PGP public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEXel0… (truncated - fetch the full key at /.well-known/security.txt)=ABCD-----END PGP PUBLIC KEY BLOCK-----