OpenBMB / OpenBMB/ChatDev

Security: requesting a private disclosure channel (no details included)

Open
#667 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
34.3k
Forks
4.3k
PR merge metrics
No merged PRs in 30d

Description

Hi — I have a security report for the workflow server and I could not find a private channel for it.

There is no SECURITY.md in this repository or in the OpenBMB/.github organisation profile, and GitHub's private vulnerability reporting is disabled here, so there is no way for me to send the details without posting them publicly.

Could you either:

  1. enable Settings → Security → Private vulnerability reporting, and I will file the full report there, or
  2. reply here (or contact me directly) with a security address you would like me to use?

I have deliberately included no technical detail in this issue. I am not disclosing publicly and I am happy to follow whatever timeline you prefer once a private channel exists.

For context on why I am asking rather than opening a normal issue: the last report of this kind (#638) was filed publicly before a fix existed, and this one is in the same area.

Thanks,
kta1kri

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Check whether SECURITY.md exists in the repository or OpenBMB/.github, then inspect Settings → Security → Private vulnerability reporting. Done means providing a private reporting channel, either by enabling GitHub's feature or replying with a security address, without exposing the undisclosed report details.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.