SECURITY.md points to private vulnerability reporting, but it appears to be disabled
- Dominant language
- TypeScript
- Stars
- 1
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
SECURITY.md asks that security problems not be filed as public issues, and directs reporters to https://github.com/dabarov/healcha/security/advisories/new. That URL 404s for me, which is what GitHub shows when private reporting isn't enabled on a repository.
I have a report that falls under the "packaged app — secrets or personal data accidentally bundled into release artifacts" item in your Scope section, and I'd rather not describe it here.
Could you enable private vulnerability reporting (Settings → Advanced Security → Private vulnerability reporting), or point me at a private channel? I have a tested patch ready and can open a PR once you've seen the details.
As far as I can tell no published release is affected, so there's no urgency from my side.
Contributor guide
Research direction
Read SECURITY.md and verify the private vulnerability reporting URL in the repository settings. Done means private vulnerability reporting is enabled, or SECURITY.md points reporters to a confirmed private channel so the reported packaged-app issue and tested patch can be shared safely.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100