SciSharp / SciSharp/BotSharp

Security issue – request for private disclosure channel

Open
#1,373 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C#
Stars
3.1k
Forks
651
Avg merge
15h 2m
Merged PRs (30d)
36

Description

I recently audited this project and found several security vulnerabilities. I would like to report them privately so they can be fixed before any public disclosure.

I noticed the repository currently lacks:

  • A SECURITY.md file
  • A vulnerability disclosure policy
  • Security-related issue templates or labels

Could you advise:

  1. Is there a preferred email or private channel where I can send the detailed vulnerability report?
  2. Would you prefer I use the GitHub Security Advisory feature instead?
  3. Would you consider adding a SECURITY.md to guide future reporters?

Thank you!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the requested SECURITY.md, vulnerability disclosure policy, and security-related issue templates or labels. Confirm the maintainers' preferred private reporting channel and whether GitHub Security Advisories should be used. Done means the repository provides decided, actionable guidance for future vulnerability reporters.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.