Dispute a finding
Findings here are derived mechanically, and mechanical derivation gets things wrong. If one is wrong, say so and it moves.
Last updated 2026-09-04. This page is also the route for a legal notice, a privacy question, and a security report about the site itself.
If your organisation is named here
If your organisation is named anywhere on this site and you want to answer what a page says, send us the answer and we will publish it beside the finding, whether or not we agree with it. You do not have to show us a mistake first.
Context we would publish gladly: that the edit was a correction the programme asked for, that a range was restructured rather than widened, that the second advisory superseded the first, that a product line was renumbered. Any of those changes what a reader should conclude, and none requires us to agree with you first.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
Where to send it
- Or email security@patchdrift.io. Anonymous reports are fine.
An upheld dispute is fixed in the classifier, not in an exception list, so one correction moves every record with the same shape and the published totals with it. Corrections are logged on the method page.
The corrections policy
Four statements, published so they can be held against us.
- Every finding on this site is derived mechanically, by comparing a record's published state against its current state in the publisher's own git history. No finding is written, reviewed or approved by a person before it appears.
- Mechanical derivation gets things wrong. Every false-positive class this site refuses was found by shipping a wrong result first, and there is very likely another one we have not caught.
- A dispute is answered against the commit pair, not against our opinion. Pull the record at the commit the finding names and at the state it was published in; if those two blobs do not show what we say they show, the finding is wrong and we withdraw it.
- An upheld dispute is fixed in the classifier rather than in an exception list, so one correction moves every affected record and the published totals with it, and the change is written into the method changelog with the headline figure before and after. A correction cannot be made silently.
The refusal classes on the method page are what that policy has produced so far. Every one exists because a wrong result was published first and somebody caught it, and each is pinned with a positive and a negative test so the same wrong result cannot come back.
Disagreeing with a finding is not the same as showing it wrong, and the two are treated differently. If the record did change and you think the change was right, that is a reply and we publish it. If the record did not change the way we say it did, that is a correction and we make it.
What settles it
Every finding names the upstream commit it came from, and the upstream catalogs are public. A dispute reduces to a commit pair: the record as first published, and the record at the commit we name. If we read them wrong, the evidence is in the pair.
- CVE records: CVEProject/cvelistV5
- CISA KEV: cisagov/kev-data
- GitHub advisories: github/advisory-database
Include, if you can:
- the CVE or GHSA id
- the vendor and product as we render it
- what is wrong: the version never moved, the two versions are not comparable, a value is misread, or the wrong publisher is named
- what the record actually says, ideally at both commits
This page reflects the 2026-09-07 snapshot at catalog commit 1f78fd2580c1. The recipe for pulling any record at any commit is on the method page.
A problem with the site itself
Same routes. Please keep testing proportionate: this is a free public tool, so demonstrate a resource-exhaustion issue with arithmetic rather than by taking it down for everyone else. A machine-readable version of this page is at /.well-known/security.txt.
Use your own test inputs. Saved reviews can contain private inventory and notes. Reviews stay in the browser; URLs can reach host logs, there are no accounts and no cookies, and a watchlist is encoded in its own URL rather than in any table. Proportionate, good-faith testing reported to us is welcome and we will not pursue it.