MoonshotAI / MoonshotAI/kimi-code

How to report security vulnerabilities? GHSA option is currently disabled.

Open
#2,117 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
7.5k
Forks
1.2k
Avg merge
11h 53m
Merged PRs (30d)
350

Description

Hi,

I'd like to privately report a security vulnerability in the Kimi Code CLI (@moonshot-ai/kimi-code). Your SECURITY.md lists GitHub Security Advisories as the preferred channel, but private vulnerability reporting does not appear to be enabled on MoonshotAI/kimi-code, the "Report a vulnerability" option isn't available, so I can't open a private advisory there.

Could you enable private vulnerability reporting on the repo (Settings → Security → Private vulnerability reporting).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Open the MoonshotAI/kimi-code repository settings and navigate to Settings → Security → Private vulnerability reporting. Confirm that private vulnerability reporting is enabled and that the “Report a vulnerability” option is available for submitting security advisories.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
1/5
Estimated time
Under an hour
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.