adoptium / adoptium/aqa-tests

Reporting a vulnerability

Open
#4,501 1 comment 0 reactions 0 assignees View on GitHub
triage required
Dominant language
HTML
Stars
155
Forks
346
Avg merge
2d 9h
Merged PRs (30d)
36

Description

Hello!

I hope you are doing well!

We are a security research team. Our tool automatically detected a vulnerability in this repository. We want to disclose it responsibly. GitHub has a feature called **Private vulnerability reporting**, which enables security research to privately disclose a vulnerability. Unfortunately, it is not enabled for this repository.

Can you enable it, so that we can report it?

Thanks in advance!

PS: you can read about how to enable private vulnerability reporting here: https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

Contributor guide

Open the contributing guide

Research direction

Start with GitHub's documentation on configuring private vulnerability reporting for a repository, linked in the issue. Enable private vulnerability reporting for adoptium/aqa-tests, and consider the work done when security researchers can submit a private vulnerability report through the repository.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.