Content policy

The public record exists so defenders can reproduce and fix vulnerabilities. Content that serves offense instead of defense is removed.

Allowed content

  • Security findings pinned to an exact commit of a public repository.
  • Reproduction steps, proof-of-concept snippets, and supporting evidence that let a maintainer or reviewer confirm the issue.
  • Affected version ranges, CWE/CVE identifiers, and vendor notification dates.
  • Reviewer verdicts and the notes needed to justify them.

Prohibited content

  • Weaponized malware, droppers, or turnkey exploit kits. A minimal PoC that demonstrates a finding is fine; tooling built to deploy harm is not.
  • Exfiltrated data: personal data, customer records, or anything taken from a system without authorization.
  • Secrets and credentials - API keys, tokens, private keys, passwords. Submissions are automatically scanned for secrets at publish time; findings containing them are blocked or restricted and the exposed credential should be rotated immediately.

Takedowns and appeals

Anyone can report content from an account via the <.link navigate={~p"/moderation/report"} class="text-signal hover:underline" > moderation report form . Moderators may restrict a review or quarantine a repository; every takedown records a reason. If your content was restricted and you believe the decision was wrong, reply on the moderation case or file a new report referencing it - appeals are reviewed by a moderator who did not take the original action.