docs: OpenThreat, one file a security tool serves about what it found in the open (#167)

* docs: OpenThreat, one file a security tool serves about what it found in the open

Twelve rules that degrade and two that do not: a subject is public or it
is not in the file (no private repos, no customer servers, no paid users'
scans), and a secret is never located while it is open (rule, severity,
subject, status only; no location, message or excerpt). Four kinds:
finding, attack, indicator, advisory. Status open, fixed, mitigated,
blocked, withdrawn; a withdrawn threat stays a while so directories
retract it. Announcing is on by default with a one-switch opt-out in the
tool's own settings. Discovery at /.well-known/openthreat.json,
rel="openthreat", or a handed URL; origin is the verification. Mapped
against SARIF, STIX 2.1 and CSAF rather than replacing them.

First reporter: threatcrush.com/discovery (its own PR). First directory:
nichedb.dev/c/threats (its own PR). Registered in DOC_SLUGS, NAV,
STATIC_ROUTES and llms.txt.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014cmNRtR2vL1p89dbVQ7FZJ

* ci: trigger workflows

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Anthony Ettinger 2026-09-12 20:30:22 -07:00 • committed by GitHub
parent 938bd5f632
commit 0fe1d423df
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
6 changed files with 375 additions and 0 deletions

View file

@ -21,6 +21,7 @@ export const DOC_SLUGS = [
"openmcp",
"openaccess",
"openserver",
"openthreat",
"openfile",
"opendisk",
"opencoupon",