Skip to content

Security: omerdvd/ManagedBlockList

SECURITY.md

Security Policy

Supported Versions

As this is a live repository of DNS blocklists, security updates and corrections are applied primarily to the main branch.

Version Supported
Main
< 1.0

Reporting a Vulnerability

I take the security and integrity of these blocklists seriously. If you discover a security vulnerability—such as a way to maliciously bypass the filters, a script injection in the management tools, or a false-positive that could be leveraged for an attack—please follow the steps below:

Disclosure Process

  1. Do not open a public Issue. To protect users, please report the vulnerability privately.
  2. Email the report: Please send a detailed description of the vulnerability to cold.gear1358@fastmail.com.
  3. Details to include:
    • A description of the issue.
    • Steps to reproduce the vulnerability (Proof of Concept).
    • Potential impact on users using the lists.

What to Expect

  • Acknowledgement: I will acknowledge receipt of your report within 48-72 hours.
  • Triage: I will investigate the report and determine the severity.
  • Remediation: If the vulnerability is verified, I will work on a fix and notify you once it is deployed.

Scope

This policy covers:

  • The DNS block and allow lists contained in this repository.
  • Any automation scripts (Python, Bash, etc.) used to generate or validate the lists.
  • Deployment workflows (GitHub Actions) within this repo.

Preferred Hyphen Usage

Please note that all documentation in this repository uses standard hyphens (-) for consistency and compatibility.


Thank you for helping keep this project and its users secure!

There aren't any published security advisories