amondnet / amondnet/vercel-action
[Security] Request for private disclosure channel
- Lingua principale
- TypeScript
- Stelle
- 765
- Fork
- 116
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
I am a security researcher and have identified a potential vulnerability in this project. Following the principles of [Coordinated Vulnerability Disclosure (CVD)](https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure), I would like to report this privately to allow your team time to investigate and address the issue before it becomes public knowledge.
Currently, I don't see a SECURITY.md file or the "Private vulnerability reporting" feature enabled for this repository.
Could you please provide a preferred method for private communication? For example, an email address dedicated to security or maintainer contact.
Alternatively, you can enable [Private Vulnerability Reporting](https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability) in your repository settings, which allows us to discuss this through a private GitHub advisory.
I have a full report ready with reproduction steps and impact analysis. To protect your users, I will not post any technical details of the vulnerability here in this public issue.
Looking forward to hearing from you.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.