As this is a live repository of DNS blocklists, security updates and corrections are applied primarily to the main branch.
| Version | Supported |
|---|---|
| Main | ✅ |
| < 1.0 | ❌ |
I take the security and integrity of these blocklists seriously. If you discover a security vulnerability—such as a way to maliciously bypass the filters, a script injection in the management tools, or a false-positive that could be leveraged for an attack—please follow the steps below:
- Do not open a public Issue. To protect users, please report the vulnerability privately.
- Email the report: Please send a detailed description of the vulnerability to cold.gear1358@fastmail.com.
- Details to include:
- A description of the issue.
- Steps to reproduce the vulnerability (Proof of Concept).
- Potential impact on users using the lists.
- Acknowledgement: I will acknowledge receipt of your report within 48-72 hours.
- Triage: I will investigate the report and determine the severity.
- Remediation: If the vulnerability is verified, I will work on a fix and notify you once it is deployed.
This policy covers:
- The DNS block and allow lists contained in this repository.
- Any automation scripts (Python, Bash, etc.) used to generate or validate the lists.
- Deployment workflows (GitHub Actions) within this repo.
Please note that all documentation in this repository uses standard hyphens (-) for consistency and compatibility.
Thank you for helping keep this project and its users secure!