Skip to content
Registry StackDocsDocumentation preview

Report a vulnerability

View as Markdown

Report a suspected Registry Stack vulnerability privately. Never open a public issue or pull request for a suspected credential disclosure, auth bypass, audit redaction failure, source connector data leakage, or signing-key handling bug.

Use the private disclosure channel for anything in scope on this page. If you are unsure whether a behavior is exploitable, report it privately. Use a public product issue only for a known, non-exploitable gap that does not include sensitive reproduction details.

Gather what the report needs before you open the channel:

  • The affected commit or release tag.
  • The config shape involved (redact secret values before you paste anything).
  • Reproduction steps.
  • The impact you observed or expect.

Do not include live credentials, bearer tokens, API keys, private keys, or raw registry records in the report.

  1. Report privately through GitHub Security Advisories.
  2. If GitHub Security Advisories is unavailable, contact the maintainer through an existing private project channel instead of opening a public issue or pull request.
  3. Include the affected commit, config shape, reproduction steps, and impact from the checklist above.

Registry Stack aims to acknowledge private reports within 5 business days.

Authentication bypass, credential disclosure, audit redaction failure, audit integrity failure, signing-key handling bugs, source connector data leakage, and privacy regressions that expose raw subject identifiers.

Known pilot limitations, such as no revocation service, no /.well-known/jwt-vc-issuer endpoint, and no built-in data-subject erasure workflow, are product gaps, not vulnerabilities, unless they create an exploitable security or privacy issue beyond the documented limitation.