OpenDevIndex accepts reports about vulnerabilities in repository automation, parsers, generated indexes, or contribution workflows.
Do not publish secrets, exploit payloads targeting real systems, or credentials in issues or pull requests.
For content entries, security claims should link to primary advisories, vendor documentation, CVEs, or reputable research whenever possible.