Security researcher launches public disclosure ledger: vulnerability reports auto-publish 30 days after vendor report

dyn___ · x · 2026-09-02

Security researcher degrigis argues that responsible disclosure is becoming "a bit of a circus" and is experimenting with a new model: a Public Disclosure Ledger on Artiphishell where every vulnerability reported to a vendor is logged the day it goes out. The write-up stays sealed for 30 days, then publishes automatically, with the clock starting at report time rather than when the vendor responds. Extensions are granted only when a vendor shows a fix is genuinely in flight and asks in writing.

Each sealed row carries a SHA-256 hash of the report, letting anyone verify the published text matches what was committed on day one. The ledger currently lists 5 findings inside the window — 3 critical and 2 medium — all in JFrog Artifactory Pro, with CVEs TBD.

Original post →

More from Safety

Safety channel →