agentscope-ai / agentscope-ai/agentscope-runtime
[Security] How can I report a vulnerability privately? (no SECURITY.md / private reporting disabled)
オープン
- 主要言語
- Python
- スター
- 863
- フォーク
- 168
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Hi maintainers — I believe I've found one or more security vulnerabilities in agentscope-runtime and would like to disclose them privately and coordinate a fix.
There's currently no SECURITY.md and GitHub "Private vulnerability reporting" isn't enabled on this repo, so I have no private channel. Could you please either enable Settings → Security → Private vulnerability reporting (I'll then submit the full write-up and PoC via the "Report a vulnerability" form), or share a security contact email?
I've intentionally omitted all technical details here to avoid public exposure before a fix is available. Thank you!
コントリビューションガイド
評価
この issue はまだ評価されていません。