Security
Security reports are welcome.
Please do not disclose an unpatched vulnerability through a public GitHub issue.
Report a vulnerability
For vulnerabilities affecting joshternet.org, the Joshternet specifications, or project infrastructure, email:
Please include enough information to reproduce and understand the issue, including the affected component, relevant URLs or versions, expected and observed behavior, reproduction steps, and the potential security impact.
Do not include unrelated personal information, credentials, private keys, access tokens, or other secrets unless they are specifically necessary to demonstrate the vulnerability.
JoshBot vulnerabilities
Security vulnerabilities affecting JoshBot should be reported through GitHub Private Vulnerability Reporting.
Do not report an unpatched JoshBot vulnerability through a public bug or crawler report.
Ordinary software defects may use the JoshBot bug report.
Unexpected crawling, robots behavior, or crawler traffic may use the JoshBot crawler report.
Security contact discovery
joshternet.org also publishes a machine-readable security contact at:
/.well-known/security.txt
The canonical security contact file is available at /.well-known/security.txt.