adonisjs / adonisjs/bodyparser

Security: please enable Private Vulnerability Reporting (or share a security contact)

Open
#80 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
35
Forks
21
Avg merge
5d 15h
Merged PRs (30d)
1

Description

Hi 👋 — I've identified a security issue in @adonisjs/bodyparser that I'd like to report privately, following responsible-disclosure practice.

I tried GitHub's Private Vulnerability Reporting, but it appears to be disabled for this repository, and I couldn't find a SECURITY.md or a dedicated security contact for the project.

Could you either:

  1. Enable Private Vulnerability Reporting for this repo (Settings → Advanced Security → Private vulnerability reporting), which lets me submit the full details through a private GitHub security advisory draft; or
  2. Share a security contact (email or preferred channel) I can send the report to.

I'm intentionally not including any technical details here to avoid public disclosure before you've had a chance to review. Happy to provide everything — root cause, PoC, affected versions, and a suggested fix — as soon as a private channel is available.

Thanks for your work on AdonisJS!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Check the repository settings at Advanced Security and verify whether Private Vulnerability Reporting is enabled. Then inspect whether a SECURITY.md file or dedicated security contact exists; the issue is complete when contributors have a private reporting path, either through GitHub or documented contact details.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
documentation, security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.