Skip to content

Security: ipfs/ipfs-docs

Security

SECURITY.md

Security Policy

This repository holds the source of docs.ipfs.tech.

Reporting a vulnerability

Email your report to security@ipfs.io. Please do not open a public issue.

Include whatever you have: the page or commit affected, how to reproduce the problem, and what an attacker gets out of it. A rough report is better than no report, and we will ask if we need more.

A maintainer will confirm we received it and keep you posted while we work on a fix. We are glad to credit you, or to leave you unnamed if you would rather not be credited.

If two weeks pass and no human has replied, assume the message never reached one. Resend it, or escalate: the OpenSSF finder guide lays out the options, and CERT/CC takes reports when coordination with a project breaks down. We would rather you do that than sit on a live bug.

A vulnerability in IPFS software

If the problem is in the software the docs describe, report it to that project. Kubo, Boxo, Helia and the rest each carry their own SECURITY.md. When you are not sure which one, email security@ipfs.io and say what you saw.

Reporting abuse on a public gateway

Malware, phishing, or illegal material reachable through a public gateway is not a bug in the docs or in IPFS software. Report it to whoever runs the gateway you used. For ipfs.io and dweb.link, follow the abuse policy.

Everything else

For normal bugs, open an issue.

This repository follows the IPFS project security policy.

There aren't any published security advisories