# How we publish about other people's projects

The rules, as of 27 Sep 2026.

## Only on our own copy

featkpr runs on a copy of the project we start ourselves, with users we seed. Never on anyone else's server.

## The maintainers hear first

A report goes to the maintainers a week before it is public, with an invitation to reply. A suspected security bug goes to them privately, through the project's own security channel, and stays private for 90 days or until it is fixed.

## We follow each project's rules

Some projects forbid AI-written reports or contributions. We read the policy first and follow it. Everything we send a maintainer is written by a person, under Tim's name.

## Every report shows its work

The release it ran on, how to repeat it, what featkpr missed, and that we are not affiliated with the project.

## Ask and we stop

A maintainer who wants their project left out only has to ask: https://featkpr.com/removal
