ModelRegistry is deployed continuously from main to
modelregistry.tirup.in.
| Version | Supported |
|---|---|
main (latest) |
✅ |
| Older commits / forks | ❌ |
We do not maintain LTS branches. Please verify against the latest main before reporting.
In scope:
- XSS / injection via model fields (
data/models.ts,data/companies.ts) rendered on the site, API (/api/v1/models), RSS (/rss.xml),llms.txt - Auth / session issues, open redirects, SSRF in API routes and badges (
/api/badge/*) - Data poisoning vectors: ability to get unverified pricing, links, or weights served as trusted
- Supply-chain issues in
next.config.mjs,middleware.ts, GitHub Actions (.github/workflows/)
Out of scope:
- Spam / SEO reports about model listing content (use a Data Correction issue instead)
- Volumetric DDoS without a demonstrated exploit
- Reports that the README table is stale (run
pnpm test/ seescripts/sync-readme.js)
This project handles no secrets, payments, or user credentials. There are no API keys to leak — the REST API is intentionally public and unauthenticated.
Do NOT open a public GitHub issue.
Report privately via either:
- GitHub Private Vulnerability Reporting (preferred): https://github.com/TirupMehta/ModelRegistry/security/advisories/new
- Open a blank issue only if advisory reporting is unavailable, with no exploit details, and request a private contact.
Include:
- Affected URL / route / file (e.g.
/api/v1/models?company=...,app/models/[id]/page.tsx) - Steps to reproduce, including payload if XSS/injection
- Impact assessment
- Your environment (browser, commit SHA)
- Acknowledgement: within 48 hours
- Triage + fix or mitigation plan: within 7 days for valid High/Critical reports
- Disclosure: coordinated — please do not publish until a fix is live on
main
We credit reporters in the fix PR unless anonymity is requested. No bug bounty program is offered at this time.
- Never commit
.env,.env.local, or tokens.pnpm buildmust pass without secrets. - All external model links must be official sources (announcement / paper / Hugging Face). No URL shorteners.
- Validate new entries with
pnpm test(scripts/validate-registry.js) before opening a PR.