Trust
Security
How to report a vulnerability in OSS Graveyard, and how we protect your account and data.
Reporting a vulnerability
If you find a security issue in this website, please tell us privately before disclosing it:
- Use the contact form with the topic “Security vulnerability”. You do not need an account, but leave an email so we can reply.
- Describe the issue, the affected URL, steps to reproduce, and the impact. Do not include other people's personal data.
We aim to acknowledge reports within 3 business days and to keep you updated until the issue is fixed. We are happy to credit you once it is resolved, if you want. This is a volunteer project, so there is no paid bug bounty.
Machine-readable contact details are in security.txt.
Scope
- In scope:
ossgraveyard.devand its sign-in flows. - Out of scope: the third-party projects listed in the catalogue (report those to their maintainers), GitHub/GitLab/Bitbucket/Codeberg, AWS and Google services, denial-of-service, social engineering, and reports from automated scanners without a demonstrated impact.
Safe harbour
We will not pursue or support legal action against good-faith research that follows this policy: use only accounts you own, do not access or modify other users' data, do not degrade the service, stop and report as soon as you find an issue, and give us reasonable time to fix it before disclosure.
How we protect you
- Passwords are stored and verified by Amazon Cognito (12+ characters, lockout after repeated failures, optional authenticator-app MFA). We never see them stored or logged.
- Forge sign-in uses OAuth with PKCE and a random state. We match accounts by the provider's permanent account id, never by username or email, and request read-only scopes.
- Sessions are random tokens in
httpOnly,Secure,SameSite=Laxcookies; only a hash is stored server-side, and signing out deletes it. - Every page is served over HTTPS with HSTS and a strict Content-Security-Policy. Cross-site form submissions are rejected.
- User-submitted text is rendered as plain text, links open with
rel="noopener nofollow", and the server fetches third-party URLs through an SSRF-protected client. - All submissions are reviewed by a moderator before they are published.