Last checked 3 Oct, 18:03 UTC

Security

Two different concerns: vulnerabilities in Refledger itself, and what we do when the ledger records a live attack on someone else's action.

Report a vulnerability in Refledger

If you find a security issue in the crawler, the log, the verifier, this site, or related infrastructure, report it privately. Preferred:GitHub private vulnerability reporting. We aim to acknowledge receipt within 72 hours.

Out of scope: third-party repositories we observe, GitHub itself, and public tag movement we did not cause. Good-faith researchers who follow this process and give us a reasonable chance to respond before public disclosure are covered by our safe harbour statement inSECURITY.md.

Researchers can also find contact details in/.well-known/security.txt.

When we detect a live attack

When the ledger records a high-severity or otherwise notable tag movement that may indicate compromise, we contact the repository maintainer via their published security contact, contact GitHub Security, and wait 72 hours before publishing analysis, correlation, or commentary. The raw log entry still publishes automatically and immediately: the log is append-only, and the public fact (that a public tag now points at a different public commit) is already visible on GitHub.

We never name a suspected attacker, never assert that a repository is compromised, and never grade an action. We state what moved, when we observed it, and what the content difference was. Full policy:SECURITY.md.

How the signing key is protected

Daily heads are signed with Ed25519. The private seed lives only as the GitHub Environment secret REFLEDGER_SIGNING_KEY on the ledger environment (main branch only), never as a repository-level secret. An offline age-encrypted backup is kept off the runner. The public key is published for independent verification.

Check our work

  • Verify the published ledger in your browser or with the CLI.
  • Read every disclosed mistake on Incidents.