Security

Responsible Disclosure

How to report a security vulnerability so it can be fixed before it's exploited.

  1. Home
  2. Responsible Disclosure

Scope

This applies to security issues affecting Digital World reference implementations (see the repositories under gitlab.com/digitalworld) or the core network infrastructure described in the Engineering Specification. Issues in a specific provider's own app or service should be reported to that provider directly - see Digital Providers.

How To Report

If you believe you've found a genuine security vulnerability, please open a confidential issue on the relevant GitLab repository, or raise it privately through an open council meeting rather than disclosing it publicly. Include enough detail to reproduce the issue and let us know how to reach you.

What We Ask

  • Give us a reasonable opportunity to investigate and address an issue before any public disclosure.
  • Avoid accessing, modifying, or deleting data that isn't your own while testing.
  • Don't perform testing that could degrade service for other members.

What To Expect

Reports are reviewed by the relevant provider or the network's governance councils. Response times vary since Digital World is an open network of independent providers rather than a single company - see Who Operates The Website.