IntelLabs / IntelLabs/Xe-Forge
Security: how to report a vulnerability (private reporting disabled)
- Dominant language
- Python
- Stars
- 21
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Hi maintainers,
I'm a security researcher (Moshe Levi, LevinityCyber) with a coordinated security
report for Xe-Forge. I'm not including any vulnerability details in this public issue.
Your SECURITY.md points to Intel's vulnerability-handling guidelines, but I'd prefer
a direct, private channel for this repo. GitHub Private Vulnerability Reporting is not
enabled here (Security > Advisories has no "Report a vulnerability" option).
Could you please either:
1. Enable GitHub Private Vulnerability Reporting on this repo
(Settings > Code security > Private vulnerability reporting), or
2. Confirm the best private contact for a coordinated disclosure on Xe-Forge?
I'll send the full write-up and a reproducible proof-of-concept as soon as there's a
private channel. Requesting standard coordinated disclosure and credit as
"Moshe Levi, LevinityCyber".
Thanks!
Moshe@levinitycyber.com
Contributor guide
Research direction
Start by reading SECURITY.md and checking the repository's Settings > Code security > Private vulnerability reporting option. Confirm that a private reporting channel is available and that SECURITY.md clearly directs researchers to it; otherwise document the approved private contact or reporting path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100