Disclosure policy
How we handle the vulnerabilities we find
Short version: findings belong to the project. We never publish them, never set deadlines and only show proofs of concept to people who can fix the code.
Who sees a report
A scan report is available only at its private link, which contains a random identifier. Reports are not listed anywhere, are excluded from search engines and are not shared with third parties other than the AI model provider that processes the code.
Anyone can start a scan of a public repository, including people who don't maintain it. That's why reports are built to help defenders first: they explain the bug, its root cause and a fix, while reproducers stay hidden until someone proves write access by committing a token file to the repository.
Enrolled projects
Reports for enrolled projects go by email to the confirmed primary contact and up to five CC addresses. Email confirmation and proof of write access are both required before any report is sent.
No deadlines
Findings are generated by AI models and are not reviewed by humans. We don't think it's fair to put a disclosure clock on findings nobody has validated, so we never set one. When and how to fix and disclose is entirely the project's decision.
We don't publish
We don't publish findings, write advisories, file public issues or request CVEs on a project's behalf. If you want to request a CVE for something we found, you're welcome to — crediting the finding ID is optional.
AI-assisted reporting rules
Our reports follow the guidance major projects have published for AI-assisted reports, including the Linux kernel's: summary first, verifiable impact rather than speculation, a candidate patch, the introducing commit for a Fixes: tag, and reproducers shared only with maintainers. If you forward a finding to a project, please verify it yourself first.
Retention
Scan reports are kept for 90 days, enrolled projects' reports for as long as the project stays enrolled. Maintainers can ask us to delete any report: hello@ossscanner.org.
Vulnerabilities in ossscanner.org
If you find a security issue in this service itself, please email hello@ossscanner.org. We'll reply within a few days and credit you if you wish.