Security you can check

OpenWhistle protects people who report wrongdoing. This page shows what that protection rests on, where it is still weak, and how to report a flaw.

Why you can trust it

Claim How it holds Check it
No IP address is stored Four layers, from nginx to the database. Anonymity layers
Reporter times are the day only Stored as a UTC date, never a time. Timestamps
Attachment metadata is removed Cleaned before storage; the pixels stay unchanged. Attachments
Nothing leaves the server unasked Every outbound request is opt-in and listed. Outbound requests
The image is the code you read Built in public CI and signed with cosign. Image signatures
The code is scanned On every pull request: CodeQL and ruff's Bandit rules on the code, pip-audit on every locked dependency, Trivy on the container image, zizmor on the CI workflows. CodeQL, pip-audit and Trivy run weekly too. The workflows, CodeQL runs
A guard that cannot fail is found Before a release, every new guard is broken on purpose. A test that stays green is rewritten. The mutation audit

Open gaps

  • There is one maintainer, so security changes get no second human review.
  • There has been no external audit yet.
  • File integrity checks catch accidents, not attackers: they are not tamper-proof.
  • The demo is public: anyone can read what it holds until the next reset.
  • On Kubernetes, the ingress must log at crit, or it logs client IP addresses.

Close a gap.

Report a vulnerability

Report it privately through GitHub's private vulnerability reporting. Never open a public issue: it shows the flaw to everyone before a fix exists.

Step Within
Acknowledge your report 48 hours
Assess it and tell you the plan 7 days
Release a fix for a critical or high issue 14 days

The full policy is in SECURITY.md. For tools, the reporting channel is in security.txt (RFC 9116).

Research is welcome, and unpaid

You may test OpenWhistle and report what you find. There is no payment: OpenWhistle is a volunteer project, and every report serves the people who rely on it. With your consent, we credit you in the advisory and in SECURITY.md. Test on your own installation, never on the public demo's other visitors.