Acceptable Use Policies Github Active Malware Or Exploits (GitHub)

Open Legal LibraryUpdated 24 Oct 2025

The GitHub Active Malware or Exploits Policy prohibits the use of GitHub’s platform to deliver malware or facilitate unlawful attacks that cause technical harm, while still allowing dual-use content for legitimate security research and educational purposes. Maintained by GitHub as part of its Acceptable Use Policies, it balances protecting the community against abuse with supporting open security research and responsible disclosure practices.

[company name] Active Malware or Exploits

Being part of a community includes not taking advantage of other members of the community. We do not allow anyone to use our platform in direct support of unlawful attacks that cause technical harms, such as using [company name] as a means to deliver malicious executables or as attack infrastructure, for example by organizing denial of service attacks or managing command and control servers. Technical harms means overconsumption of resources, physical damage, downtime, denial of service, or data loss, with no implicit or explicit dual-use purpose prior to the abuse occurring.

Note that [company name] allows dual-use content and supports the posting of content that is used for research into vulnerabilities, malware, or exploits, as the publication and distribution of such content has educational value and provides a net benefit to the security community. We assume positive intention and use of these projects to promote and drive improvements across the ecosystem.

In rare cases of very widespread abuse of dual-use content, we may restrict access to that specific instance of the content to disrupt an ongoing unlawful attack or malware campaign that is leveraging the [company name] platform as an exploit or malware CDN. In most of these instances, restriction takes the form of putting the content behind authentication, but may, as an option of last resort, involve disabling access or full removal where this is not possible. We will also contact the project owners about restrictions put in place where possible.

Restrictions are temporary where feasible, and do not serve the purpose of purging or restricting any specific dual-use content, or copies of that content, from the platform in perpetuity. While we aim to make these rare cases of restriction a collaborative process with project owners, if you do feel your content was unduly restricted, we have an appeals process in place.

To facilitate a path to abuse resolution with project maintainers themselves, prior to escalation to [company name] abuse reports, we recommend, but do not require, that repository owners take the following steps when posting potentially harmful security research content:

Clearly identify and describe any potentially harmful content in a disclaimer in the project’s README.md file or source code comments.

Provide a preferred contact method for any 3rd party abuse inquiries through a SECURITY.md file in the repository (e.g. "Please create an issue on this repository for any questions or concerns"). Such a contact method allows 3rd parties to reach out to project maintainers directly and potentially resolve concerns without the need to file abuse reports.

[company name] considers the npm registry to be a platform used primarily for installation and run-time use of code, and not for research.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

United States note

This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.

Jurisdiction
United States of America
Source
Acceptable Use Policies Github Active Malware Or Exploits (GitHub)
from GitHub
Document info
HTML document. Document created on Mon Oct 6th, 2025. Last updated on Fri Oct 24th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026
US
Firefox Relay Privacy Notice by Mozilla
This privacy notice outlines how an email alias service handles user data, including the processing of email messages and account information. It details data collection for Firefox Accounts, interaction logs, and technical device data while clarifying that email content is not read or stored.
Updated 13 Aug 2026
US
Acceptable Use Policies Github Threats Of Violence And Gratuitously Violent Content (GitHub)
This policy prohibits users from using a platform to organize or promote acts of violence, including threats of physical harm, sexual violence, or death. It restricts the posting of graphic depictions of violence against humans or animals while providing exceptions for educational, documentary, or historical purposes provided clear warnings are included.
Updated 13 Aug 2026
England & Wales
Firefox Focus and Firefox Klar Privacy Notice by Mozilla
This privacy notice explains how a browser developer processes technical, interaction, and browsing data. It details user rights under data protection laws and provides options for managing data collection and search preferences.
Updated 13 Aug 2026
US
Websites, Communications & Cookies Privacy Notice by Mozilla
This privacy notice outlines how a company handles information collected through its websites, mobile apps, and digital communications. It covers data collection for job applications, contributor profiles, and payment processing while explaining the use of cookies and tracking tools.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.