MarlinFirmware / MarlinFirmware/AutoBuildMarlin
Enable private vulnerability reporting for a security disclosure
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 285
- Forks
- 70
- PR merge metrics
- No merged PRs in 30d
Description
Hi, I would like to report a security vulnerability in the Auto Build Marlin extension privately.
This repository does not have a SECURITY.md or GitHub Private Vulnerability Reporting enabled, so there is no private channel to reach the maintainers. Could you either:
- Enable Private Vulnerability Reporting (Settings > Code security and analysis > Private vulnerability reporting), so I can file a private advisory, or
- Share a security contact email?
I am not including any technical details here to avoid public exposure before a fix. I follow coordinated disclosure and can send the full report and a proof of concept as soon as there is a private channel. I would also like a CVE and credit once it is confirmed.
Thanks,
Mykhailo Kholiev
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the repository's GitHub Settings > Code security and analysis page and confirm that no SECURITY.md or private reporting channel is present. Enable Private Vulnerability Reporting or add a security contact path, then verify that a reporter can submit vulnerability details privately.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, javascript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100