Skip to content
Top

Dispute a finding

If a finding is wrong, tell us and we correct it. This page is also where to send a reply, a legal notice, a privacy question or a security report about the site.

Last updated 2026-09-04.

If your organisation is named here

If your organisation is named anywhere on this site and you want to answer what a page says, send us the answer and we will publish it beside the finding, whether or not we agree with it. You do not have to show us a mistake first.

Context we would publish gladly: that the edit was a correction the programme asked for, that a range was restructured rather than widened, that a second advisory superseded the first, that a product line was renumbered. Any of those changes what a reader should conclude, and none requires our agreement.

Where to send it

The same routes, machine-readable, are in /.well-known/security.txt.

The corrections policy

Four statements, published so they can be held against us.

  1. Every finding on this site is derived mechanically, by comparing a record's published state against its current state in the publisher's own git history. No finding is written, reviewed or approved by a person before it appears.
  2. Software gets things wrong. Every one of the filter-out reasons this site applies was found by publishing a wrong result first, and there is very likely another we have not caught.
  3. A dispute is decided by the record itself: the record as first published, and the record at the edit we name. If those two do not show what we say they show, the finding is wrong and we withdraw it.
  4. An upheld dispute is fixed in the rule, not by hand-editing one record, so every affected record and every published total moves with it, and the change is written into the method changelog with the headline figure before and after. A correction cannot be made silently.

The reasons we filter out a change (How it works →) are the record of that policy: each one is a wrong result somebody caught.

Disagreeing with a finding is not the same as showing it wrong. If the record did change and you think the change was right, that is a reply and we publish it; if it did not change the way we say, that is a correction and we make it.

What settles it

Every finding names the edit it came from. The three sources are public:

Include, if you can:

The commands for pulling any record at any commit: How it works: check a finding yourself →

A problem with the site itself

A security report goes the same way as everything else: where to send it ↑

Test with your own inputs, not a real inventory (what the site stores →). Good-faith, proportionate testing is welcome and will not be pursued.