amondnet / amondnet/vercel-action

[Security] Request for private disclosure channel

Aperta
#370 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
TypeScript
Stelle
765
Fork
116
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

I am a security researcher and have identified a potential vulnerability in this project. Following the principles of [Coordinated Vulnerability Disclosure (CVD)](https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure), I would like to report this privately to allow your team time to investigate and address the issue before it becomes public knowledge.

Currently, I don't see a SECURITY.md file or the "Private vulnerability reporting" feature enabled for this repository.

Could you please provide a preferred method for private communication? For example, an email address dedicated to security or maintainer contact.

Alternatively, you can enable [Private Vulnerability Reporting](https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability) in your repository settings, which allows us to discuss this through a private GitHub advisory.

I have a full report ready with reproduction steps and impact analysis. To protect your users, I will not post any technical details of the vulnerability here in this public issue.

Looking forward to hearing from you.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.