dabarov / dabarov/healcha

SECURITY.md points to private vulnerability reporting, but it appears to be disabled

Open
#1 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
1
Forks
1
PR merge metrics
No merged PRs in 30d

Description

SECURITY.md asks that security problems not be filed as public issues, and directs reporters to https://github.com/dabarov/healcha/security/advisories/new. That URL 404s for me, which is what GitHub shows when private reporting isn't enabled on a repository.

I have a report that falls under the "packaged app — secrets or personal data accidentally bundled into release artifacts" item in your Scope section, and I'd rather not describe it here.

Could you enable private vulnerability reporting (Settings → Advanced Security → Private vulnerability reporting), or point me at a private channel? I have a tested patch ready and can open a PR once you've seen the details.

As far as I can tell no published release is affected, so there's no urgency from my side.

Contributor guide

Open the contributing guide

Research direction

Read SECURITY.md and verify the private vulnerability reporting URL in the repository settings. Done means private vulnerability reporting is enabled, or SECURITY.md points reporters to a confirmed private channel so the reported packaged-app issue and tested patch can be shared safely.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
documentation, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.