OpenAI blog 06月12日 10:56
Scaling security with responsible disclosure
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

OpenAI宣布了一项针对第三方软件漏洞披露的政策,旨在通过合作、尊重和帮助更广泛的生态系统来促进安全的数字环境。该政策涵盖了通过自动化和手动代码审查发现的漏洞,以及在使用第三方软件和系统时发现的问题。OpenAI将采用开发者友好的披露时间表,并预留公开披露的权利。此举反映了随着AI系统在发现和修复安全漏洞方面变得越来越有效,协调漏洞披露将成为一项必要实践。

🛡️ 政策概述:OpenAI推出了Outbound Coordinated Disclosure Policy,详细说明了如何负责任地报告在第三方软件中发现的安全问题。该政策旨在通过合作、尊重和帮助更广泛的生态系统来促进安全的数字环境。

🔍 覆盖范围:该政策涵盖了通过自动化和手动代码审查发现的漏洞,以及在使用第三方软件和系统时发现的问题。OpenAI将验证和确定调查结果的优先级,并与供应商联系以进行披露。

⏳ 披露时间:OpenAI采取了开发者友好的披露时间表,默认情况下保持开放时间,以适应漏洞发现的不断发展,尤其是在AI系统变得更有效时。但保留在必要时公开披露的权利。

🤝 原则:OpenAI的原则包括注重影响、合作、默认情况下谨慎、高规模和低摩擦,并在相关时提供归属。OpenAI致力于构建一个更健康、更安全的生态系统。

June 3, 2025

Security

OpenAI’s approach to reporting vulnerabilities in third-party software, built on integrity, cooperation, and scale.

We are publishing an Outbound Coordinated Disclosure Policy that we will follow when disclosing vulnerabilities to third-parties.

At OpenAI, we are committed to advancing a secure digital ecosystem. That’s why we’re introducing our Outbound Coordinated Disclosure Policy, which lays out how we responsibly report security issues we discover in third-party software. We're doing this now because we believe coordinated vulnerability disclosure will become a necessary practice as AI systems become increasingly capable of finding and patching security vulnerabilities. Systems developed by OpenAI have already uncovered zero-day vulnerabilities in third-party and open-source software, and we are taking this proactive step in anticipation of future discoveries.

Whether surfaced through ongoing research, targeted audits of open source code we leverage, or automated analysis using AI tools, our goal is to report vulnerabilities in a way that’s cooperative, respectful, and helpful to the broader ecosystem.

What the policy covers

This policy lays out how we disclose issues found in open-source and commercial software through automated and manual code review, as well as discoveries arising from internal usage of third-party software and systems.

It explains:

  • How we validate and prioritize findings
  • How we contact vendors and the disclosure mechanics we follow
  • When and how we go public (non-public first, unless the details demand otherwise)
  • Our principles, which include being impact oriented, cooperative, discreet by default, high scale and low friction, and providing attribution when relevant.

We take an intentionally developer-friendly stance on disclosure timelines and have elected to leave timelines open-ended by default. This approach reflects the evolving nature of vulnerability discovery, particularly as AI systems become more effective at reasoning about code, its strengths and weaknesses, and generating reliable patches to increase code security. We anticipate our models detecting a greater number of bugs of increasing complexity, which may require deeper collaboration and more time to resolve sustainably. We’ll continue working with software maintainers to develop disclosure norms that balance urgency with long-term resilience. We still reserve the right to disclose when we determine there is, for example, public interest in doing so.

Looking ahead

We will keep improving this policy as we learn. If you have questions about our disclosures practices, reach out to us at outbounddisclosures@openai.com.

Security is a journey defined by continuous improvement. We’re thankful to the vendors, researchers, and community members who walk that road with us. We hope that transparent communication around our approach supports a healthier, more secure ecosystem for everyone.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

OpenAI 漏洞披露 安全 第三方软件
相关文章