Security finding
- Dominant language
- Python
- Stars
- 538
- Forks
- 112
- PR merge metrics
- No merged PRs in 30d
Description
Hey there!
I've been doing security research on dependencies and have found an issue. Could you enable [private vuln reporting](https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configuring-private-vulnerability-reporting-for-a-repository) or drop contact info here or inside a SECURITY.md file? That way I can submit the findings along with a patch (if you would like).
Thanks!
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the linked GitHub private vulnerability reporting documentation and check whether the repository already contains a SECURITY.md file. Confirm which reporting channel the maintainers will use, then document the contact path or enable private vulnerability reporting; done means security researchers have a clear private way to submit findings.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100