Skip to content

Security: indicaindependent/warheatmap

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

This project is part of the VPDLNY (Vulnerable Persons Defense League of NY) open-tools collective. Many of these tools handle OSINT data, live geopolitical feeds, or interface with social platforms — so security reports are taken seriously and acknowledged quickly.

How to report

Preferred channel: Direct message on Bluesky to @indicaindependent.bsky.social.

Please include:

  • A description of the vulnerability
  • Steps to reproduce (or a proof-of-concept if safe to share)
  • The repo + commit/version affected
  • Your preferred disclosure timeline

What to expect

  • Acknowledgment: within 7 days of report
  • Initial assessment: within 14 days
  • Fix or mitigation: target 30 days for critical, 90 days for lower-severity
  • Public disclosure: coordinated with reporter; credit given unless you prefer anonymity

Out of scope

  • Vulnerabilities in third-party dependencies — please report upstream first
  • Social-engineering or physical-access attacks against the maintainer
  • Issues in archived repositories (see repo status)

Scope

This policy covers all repositories under github.com/indicaindependent, including all production Cloudflare Workers, Bluesky bots, and public-facing tools.


VPDLNY — Information is the weapon. Used responsibly.

There aren't any published security advisories