harfbuzz / harfbuzz/ttf-parser
How to report a security issue privately?
Open
- Dominant language
- Rust
- Stars
- 792
- Forks
- 88
- PR merge metrics
- No merged PRs in 30d
Description
Hi, I found a security issue in ttf-parser. I don't see a SECURITY.md or private vulnerability reporting enabled on the repo. Is there a secure way to share the details with you, e.g. a security email or turning on GitHub private vulnerability reporting? Thanks.
Contributor guide
Research direction
Check the repository for a SECURITY.md file and review the current GitHub vulnerability-reporting settings. The issue provides no implementation entry point; done means the project has a clearly documented, private channel for submitting security details.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100