agentscope-ai / agentscope-ai/agentscope-runtime

[Security] How can I report a vulnerability privately? (no SECURITY.md / private reporting disabled)

オープン
#517 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
863
フォーク
168
PR マージ指標
30日以内にマージされた PR はありません

説明

Hi maintainers — I believe I've found one or more security vulnerabilities in agentscope-runtime and would like to disclose them privately and coordinate a fix.

There's currently no SECURITY.md and GitHub "Private vulnerability reporting" isn't enabled on this repo, so I have no private channel. Could you please either enable Settings → Security → Private vulnerability reporting (I'll then submit the full write-up and PoC via the "Report a vulnerability" form), or share a security contact email?

I've intentionally omitted all technical details here to avoid public exposure before a fix is available. Thank you!

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。