Security issue – request for private disclosure channel
Open
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 3.1k
- Forks
- 651
- Avg merge
- 15h 2m
- Merged PRs (30d)
- 36
Description
I recently audited this project and found several security vulnerabilities. I would like to report them privately so they can be fixed before any public disclosure.
I noticed the repository currently lacks:
- A
SECURITY.mdfile - A vulnerability disclosure policy
- Security-related issue templates or labels
Could you advise:
- Is there a preferred email or private channel where I can send the detailed vulnerability report?
- Would you prefer I use the GitHub Security Advisory feature instead?
- Would you consider adding a
SECURITY.mdto guide future reporters?
Thank you!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the requested SECURITY.md, vulnerability disclosure policy, and security-related issue templates or labels. Confirm the maintainers' preferred private reporting channel and whether GitHub Security Advisories should be used. Done means the repository provides decided, actionable guidance for future vulnerability reporters.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100