This policy covers vulnerabilities in the content-index repository, its validation tools, its GitHub Actions workflows, and its published metadata path. It does not decide whether a listed archive is safe or whether content should remain listed.
Report a vulnerability through GitHub private vulnerability reporting. Do not open a public issue or disclose the details before the maintainers have had time to investigate and prepare a fix.
Include the affected tool or workflow, the impact, and clear steps to reproduce the problem when you can. Use the public issue tracker for an ordinary validation or documentation bug that does not put people, data, systems, or the index process at risk.
Use the takedown form for a harmful archive, a listing or release metadata problem, an id dispute, or a request to remove content from the index. POLICY.md explains what the index can remove and what remains under the control of the release host.
The stewards are volunteers and have no on-call rota. We aim to acknowledge a private report as soon as we can, but cannot guarantee a response or fix time. We will assess the report, keep the reporter informed when there is useful news, and prepare a fix before public disclosure when possible. Please coordinate public disclosure with us when possible.