harfbuzz / harfbuzz/ttf-parser

How to report a security issue privately?

Open
#217 6 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
792
Forks
88
PR merge metrics
No merged PRs in 30d

Description

Hi, I found a security issue in ttf-parser. I don't see a SECURITY.md or private vulnerability reporting enabled on the repo. Is there a secure way to share the details with you, e.g. a security email or turning on GitHub private vulnerability reporting? Thanks.

Contributor guide

Open the contributing guide

Research direction

Check the repository for a SECURITY.md file and review the current GitHub vulnerability-reporting settings. The issue provides no implementation entry point; done means the project has a clearly documented, private channel for submitting security details.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.