Clearing Up the Rules for Security Research on GitHub

GitHub is asking the security community for input as it works to clarify its policies around exploits and malware. The goal is to give security researchers a clearer idea of what is allowed on the platform and how GitHub handles abuse reports, while keeping the platform itself safe. The company has opened a pull request in its site-policy repository for public discussion.

The proposed updates are meant to draw a sharper line between content that is actively harmful and code that is at rest and part of legitimate security research. The latter is welcome and encouraged on GitHub. The policy changes also aim to remove ambiguity around terms like "exploit," "malware," and "delivery" so that both expectations and intentions are clearer to users.

Why the Policy Is Being Revisited

GitHub sees open security research as an important part of software security, and it wants to be a neutral home for that work. The company believes that a more explicit set of rules will help researchers understand how these policies apply to their projects, and what factors go into decisions about restricting content. The revisions are designed to provide transparency into how GitHub evaluates abuse reports related to malware and exploits.

Community Input Welcome

GitHub is inviting security researchers and developers to collaborate on the proposed changes in its site-policy repository, where policy updates are typically developed in the open. Comments will be accepted for a 30-day period until 10am PT on June 1, 2021. GitHub is particularly interested in learning from the broader community about its needs and how these changes might affect their work.