Security: requesting a private disclosure channel (no details included)
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 34.3k
- Forks
- 4.3k
- PR merge metrics
- No merged PRs in 30d
Description
Hi — I have a security report for the workflow server and I could not find a private channel for it.
There is no SECURITY.md in this repository or in the OpenBMB/.github organisation profile, and GitHub's private vulnerability reporting is disabled here, so there is no way for me to send the details without posting them publicly.
Could you either:
- enable Settings → Security → Private vulnerability reporting, and I will file the full report there, or
- reply here (or contact me directly) with a security address you would like me to use?
I have deliberately included no technical detail in this issue. I am not disclosing publicly and I am happy to follow whatever timeline you prefer once a private channel exists.
For context on why I am asking rather than opening a normal issue: the last report of this kind (#638) was filed publicly before a fix existed, and this one is in the same area.
Thanks,
kta1kri
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Check whether SECURITY.md exists in the repository or OpenBMB/.github, then inspect Settings → Security → Private vulnerability reporting. Done means providing a private reporting channel, either by enabling GitHub's feature or replying with a security address, without exposing the undisclosed report details.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100