Comfy-Org / Comfy-Org/ComfyUI_frontend
Private channel for reporting a security issue
- Dominant language
- TypeScript
- Stars
- 2k
- Forks
- 699
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 490
Description
Hello maintainers,
I found a potential security issue affecting GitHub Actions workflows in this repository.
I do not want to disclose technical details publicly before maintainers have reviewed them. Could you please enable GitHub private vulnerability reporting or provide an alternative private security contact email?
I can provide a detailed report including the affected workflow paths, current commit, impact assessment, non-destructive validation steps, and suggested remediation.
Contributor guide
Research direction
Review the repository's GitHub Actions security-reporting options and determine whether GitHub private vulnerability reporting can be enabled; otherwise identify a private security contact route. No specific files or tests are named. The issue is complete when the reporter has a private channel for submitting the affected workflow paths, commit, impact assessment, validation steps, and remediation details.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100