Skip to content

Community-driven mechanism for takedown of spam/malicious servers #92

Open
@tadasant

Description

@tadasant

Some discussion here: #93

When someone publishes a malicious or spam server.json, we need a mechanism for getting it reported and taken down.

While we can rely on existing source registries that we reference (e.g. npm, pypi, etc) to pull down malicious source code, we can't rely on the same mechanism for remote servers.

Steps to do here:

  • Evaluate how other registries in the ecosystem deal with this. Likely solution is to enable community reporting of spam/malicious intent.
  • Design mechanism for making those submissions
  • Set thresholds for what meets the bar for a takedown
  • Implement

Metadata

Metadata

Assignees

No one assigned

    Labels

    go-live blockerThis issue is one we need to address prior to initial go-liveproduct requirements workUpstream of development work

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions