Affected source
Identify the affected commit, tag, file or artifact.
OPENRGD SECURITY
The canonical repository contains a draft standard and a non-actuating alpha toolchain. Security reporting therefore covers source, tooling, integrity and supply-chain issues while keeping physical-runtime responsibility explicit.
If private vulnerability reporting is unavailable, open only a minimal public issue containing [SECURITY CONTACT REQUEST] and ask for a private disclosure channel. Do not include proof-of-concept code, secrets, device addresses or exploitation details.
PRIVATE REPORT
Identify the affected commit, tag, file or artifact.
Describe impact, preconditions and the smallest useful reproduction evidence.
State whether hardware, middleware or an external Body Adapter is involved.
Include any known safe mitigation or containment path.
Flag whether public details could create immediate physical or operational risk.
Do not include secrets, personal data or unnecessary private reasoning transcripts.
PHYSICAL SAFETY
When a report involves physical actuation, the responsible embodied-runtime or Body Adapter implementation must also receive the report once identified. The canonical OpenRGD repository cannot authorize hardware execution or certify a robot as safe.
SAFE REPRODUCTION
Suspected actuation vulnerabilities should not be reproduced on live hardware unless the system is isolated, independently supervised and physical testing is necessary to establish the issue.
SUPPLY CHAIN
Unexpected changes to canonical integrity commitments should be reported.
Unexpected movement, replacement or inconsistent release identity is security-relevant.
Changes that alter validation, release or provenance behavior deserve scrutiny.
Unexpected checksums or generated outputs may indicate a broken or compromised pipeline.
Dependency-resolution changes can alter the trusted execution path.
Signing and provenance claims must remain distinguishable from plain content hashes.
PUBLIC DISCLOSURE
The canonical policy calls for a public advisory or issue after a safe fix or mitigation is available, or when coordinated disclosure is no longer possible. Public records should distinguish confirmed facts, affected versions and unresolved risk.
SOURCE OF TRUTH