Security: requesting a private channel to report a critical vulnerability (no details here)
- 主要语言
- Rust
- 星标
- 2.3k
- 派生
- 231
- 平均合并
- 2 小时 49 分钟
- 30 天内合并 PR
- 589
描述
Hi maintainers 👋
I've identified what I assess as a **critical-severity security vulnerability** in BitFun, reproduced against the current `main` branch.
I'm **intentionally withholding all technical details here** — no affected file, component, mechanism, or proof-of-concept — because publicly disclosing an unpatched issue would put current users at risk. This follows the project's own `SECURITY.md` / coordinated-disclosure policy.
I already have a complete report ready to share **privately**, including:
- Root-cause analysis and the exact location
- A working, self-contained proof-of-concept
- CVSS 3.1 scoring
- A proposed patch (diff) plus a regression test
**What I need to proceed: a private channel.** Right now the repo's `/security/advisories/new` link isn't usable by non-maintainers because **Private Vulnerability Reporting appears to be disabled**. Please do one of:
1. **Enable Private Vulnerability Reporting** — repo **Settings → Code security and analysis → Private vulnerability reporting → Enable**. I'll then submit the full report through GitHub Security Advisories; or
2. Reply with a **private security contact** (e.g. a security email) I can send the report to.
Once a private channel is open I'll hand over everything immediately, and I'm happy to coordinate a disclosure timeline after you've had a chance to review and patch.
Flagging as high priority given the severity. Thanks for building BitFun! 🙏
贡献指南
调研方向
Start with the repository's SECURITY.md and the GitHub Security Advisories private-reporting entry point mentioned in the issue. The issue is complete when a private channel is enabled or a private security contact is provided so the withheld vulnerability report, proof of concept, proposed patch, and regression test can be shared.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- rust
- 领域
- security
- Issue 类型
- 缺陷
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 15/100