Security

Security reports are welcome.

Please do not disclose an unpatched vulnerability through a public GitHub issue.

Report a vulnerability

For vulnerabilities affecting joshternet.org, the Joshternet specifications, or project infrastructure, email:

[email protected]

Please include enough information to reproduce and understand the issue, including the affected component, relevant URLs or versions, expected and observed behavior, reproduction steps, and the potential security impact.

Do not include unrelated personal information, credentials, private keys, access tokens, or other secrets unless they are specifically necessary to demonstrate the vulnerability.

JoshBot vulnerabilities

Security vulnerabilities affecting JoshBot should be reported through GitHub Private Vulnerability Reporting.

Do not report an unpatched JoshBot vulnerability through a public bug or crawler report.

Ordinary software defects may use the JoshBot bug report.

Unexpected crawling, robots behavior, or crawler traffic may use the JoshBot crawler report.

Security contact discovery

joshternet.org also publishes a machine-readable security contact at:

/.well-known/security.txt

The canonical security contact file is available at /.well-known/security.txt.