Security you can check
OpenWhistle protects people who report wrongdoing. This page shows what that protection rests on, where it is still weak, and how to report a flaw.
Why you can trust it
| Claim | How it holds | Check it |
|---|---|---|
| No IP address is stored | Four layers, from nginx to the database. | Anonymity layers |
| Reporter times are the day only | Stored as a UTC date, never a time. | Timestamps |
| Attachment metadata is removed | Cleaned before storage; the pixels stay unchanged. | Attachments |
| Nothing leaves the server unasked | Every outbound request is opt-in and listed. | Outbound requests |
| The image is the code you read | Built in public CI and signed with cosign. | Image signatures |
| The code is scanned | On every pull request: CodeQL and ruff's Bandit rules on the code, pip-audit on every locked dependency, Trivy on the container image, zizmor on the CI workflows. CodeQL, pip-audit and Trivy run weekly too. | The workflows, CodeQL runs |
| A guard that cannot fail is found | Before a release, every new guard is broken on purpose. A test that stays green is rewritten. | The mutation audit |
Open gaps
- There is one maintainer, so security changes get no second human review.
- There has been no external audit yet.
- File integrity checks catch accidents, not attackers: they are not tamper-proof.
- The demo is public: anyone can read what it holds until the next reset.
- On Kubernetes, the ingress must log at
crit, or it logs client IP addresses.
Report a vulnerability
Report it privately through GitHub's private vulnerability reporting. Never open a public issue: it shows the flaw to everyone before a fix exists.
| Step | Within |
|---|---|
| Acknowledge your report | 48 hours |
| Assess it and tell you the plan | 7 days |
| Release a fix for a critical or high issue | 14 days |
The full policy is in SECURITY.md. For tools, the reporting channel is in security.txt (RFC 9116).
Research is welcome, and unpaid
You may test OpenWhistle and report what you find. There is no payment: OpenWhistle is a volunteer project, and every report serves the people who rely on it. With your consent, we credit you in the advisory and in SECURITY.md. Test on your own installation, never on the public demo's other visitors.