cjc0013/responsible-disclosure-evidence-index
Responsible Disclosure Evidence Index This is a public-safe responsible-disclosure lane. It records our rules and links to sanitized disclosure records and non-actionable commitment notes. The current default is commitment first: when retained evidence exists, a non-actionable public commitment record gives the work a visible timestamp while technical details stay private. It does not publish exploit steps, private emails, source paths, reproduction code, raw logs, or unresolved… See the full description on the dataset page: https://huggingface.co/datasets/cjc0013/responsible-disclosure-evidence-index.
Responsible Disclosure Evidence Index
This is a public-safe responsible-disclosure lane. It records our rules and links to sanitized disclosure records and non-actionable commitment notes. The current default is commitment first: when retained evidence exists, a non-actionable public commitment record gives the work a visible timestamp while technical details stay private. It does not publish exploit steps, private emails, source paths, reproduction code, raw logs, or unresolved technical packets.
Sanitized Disclosure Records
- Linux kernel: UML vector transport GRE header boundary - Public record for a private Linux UML vector transport report involving GRE header initialization and an out-of-bounds write concern. The disclosure date and no-response review date are stated; technical details are withheld.
- Werkzeug: Windows/NTFS alternate-stream path boundary - Public record for a private Werkzeug report involving Windows/NTFS alternate-stream path-boundary handling. The disclosure date and no-response review date are stated; technical details are withheld.
These are public disclosure-lane records. They are still sanitized: no reproduction steps, exploit code, raw logs, private correspondence, secrets, or target-specific mechanics.
Public-Safe Commitments
- ChromeOS: authentication-boundary research
- actions-rust-lang/setup-rust-toolchain: high-tier GitHub Actions Rust toolchain workflow research
These are not full vulnerability disclosures. They are public-safe notices that evidence is retained and that technical details are withheld for an authorized security responder.
Rules We Follow
- New items with retained evidence start in the public-safe commitment lane.
- Private email is no longer the default prerequisite for visibility; it may still be used for an authorized responder route or follow-up when that route is clearly workable.
- Commitment records are priority and evidence-integrity records, not vulnerability advisories, exploit claims, or vendor validation claims.
- A commitment can be promoted to a sanitized disclosure record only after separate review clears that step.
- Historical disclosure records may preserve earlier email/no-response timelines from the prior workflow.
- Public notes stay non-actionable: no reproduction steps, exploit code, private correspondence, secrets, tokens, raw logs, local paths, or target-specific mechanics.
- Public records are not claiming attacker or untrusted control, current-version reachability, exploitability, severity, security effect, remediation status, or vendor validation. Reproducible vulnerable behavior is not proven in public records unless an individual record explicitly says otherwise.
- Unvalidated or partly validated work is labelled with its limits.
- Human review is required before technical details or stronger claims are published.
What Is Visible Here
- Sanitized public disclosure markdown files.
- Public-safe commitment markdown files.
- A public-safe source-ledger summary.
Current Machine-Readable State
data/finding_index.jsonlcontains 2 sanitized disclosure records.data/commitment_index.jsonlcontains 2 public-safe commitment records.data/source_ledger_index.jsonlcontains 1 public-safe ledger summary row.- No private mirrors are included in this upload.
Repository
Dataset page: https://huggingface.co/datasets/cjc0013/responsible-disclosure-evidence-index
Generated UTC: 2026-06-15T18:36:33+00:00
