Content policy
The public record exists so defenders can reproduce and fix vulnerabilities. Content that serves offense instead of defense is removed.
Allowed content
- Security findings on a public repository.
- Reproduction steps, proof-of-concept snippets, and supporting evidence that let a maintainer or reviewer confirm the issue.
- Affected version ranges, CWE/CVE identifiers, and vendor notification dates.
- Reviewer verdicts and the notes needed to justify them.
Prohibited content
- Weaponized malware, droppers, or turnkey exploit kits. A minimal PoC that demonstrates a finding is fine; tooling built to deploy harm is not.
- Exfiltrated data: personal data, customer records, or anything taken from a system without authorization.
- Secrets and credentials - API keys, tokens, private keys, passwords. Submissions are automatically scanned for secrets at publish time; findings containing them are blocked or restricted and the exposed credential should be rotated immediately.
Takedowns and appeals
Anyone can report content from an account via the moderation report form . Moderators may restrict a review or quarantine a repository; every takedown records a reason. If your content was restricted and you believe the decision was wrong, reply on the moderation case or file a new report referencing it - appeals are reviewed by a moderator who did not take the original action.