Skip to main content

Challenge the record

Corrections and security disclosure

Automated reports can be incomplete or wrong. Package maintainers and researchers should challenge unsupported conclusions and provide reproducible evidence.

Request a report correction

Open an issue in the public issue tracker when the report itself contains an incorrect version, unsupported interpretation, missing context, or stale result. Include the report URL, package version, disputed statement, and evidence supporting the correction.

Disclose a service vulnerability

Do not publish exploit details in a public issue. Use the repository's Security area to check for private reporting options and current security guidance. Provide affected routes or versions, reproduction steps, impact, and suggested mitigation.

What happens to challenged reports

A correction request is evidence, not an automatic takedown. The underlying package version and stored signals should remain identifiable. Material corrections should explain what changed rather than silently rewriting the historical record.