codeskyblue / codeskyblue/gohttpserver
Security: Please enable Private Vulnerability Reporting
- Dominant language
- JavaScript
- Stars
- 2.8k
- Forks
- 583
- PR merge metrics
- No merged PRs in 30d
Description
Hi @codeskyblue,
I am a security researcher and I have identified **two critical security vulnerabilities** in gohttpserver that I would like to report responsibly.
However, [Private Vulnerability Reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) is not currently enabled on this repository, so I cannot submit a confidential security advisory through GitHub.
**Could you please enable Private Vulnerability Reporting?** You can do this from:
**Settings > Security > Private vulnerability reporting > Enable**
This will allow me to submit the full details, proof of concept, and suggested fixes privately, so the vulnerabilities can be patched before any public disclosure.
I have also sent the details to your email address for immediate review.
Thank you for your time.
Dennis Sepede
[Securitix Solutions](https://securitixsolutions.com)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.