haskell / haskell/vscode-haskell
Enable private vulnerability reporting for a security disclosure
- Dominant language
- TypeScript
- Stars
- 597
- Forks
- 98
- PR merge metrics
- No merged PRs in 30d
Description
Hi, I would like to report a security vulnerability in this extension privately.
This repository does not have a SECURITY.md or GitHub Private Vulnerability Reporting enabled, so there is no private channel to reach the maintainers. Could you either:
1. Enable Private Vulnerability Reporting (Settings > Code security and analysis > Private vulnerability reporting), so I can file a private advisory, or
2. Share a security contact email?
I am not including any technical details here to avoid public exposure before a fix. I follow coordinated disclosure and can send the full report and a proof of concept as soon as there is a private channel. I would also like a CVE and credit once it is confirmed.
Thanks,
Mykhailo Kholiev
Contributor guide
Research direction
Check the repository's SECURITY.md status and the GitHub Settings > Code security and analysis > Private vulnerability reporting setting. Done means a private reporting channel is enabled or a security contact is documented so the reporter can submit technical details safely.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100