haskell / haskell/vscode-haskell

Enable private vulnerability reporting for a security disclosure

未关闭
#1,387 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
597
派生
98
PR 合并指标
30 天内没有已合并 PR

描述

Hi, I would like to report a security vulnerability in this extension privately.

This repository does not have a SECURITY.md or GitHub Private Vulnerability Reporting enabled, so there is no private channel to reach the maintainers. Could you either:

1. Enable Private Vulnerability Reporting (Settings > Code security and analysis > Private vulnerability reporting), so I can file a private advisory, or
2. Share a security contact email?

I am not including any technical details here to avoid public exposure before a fix. I follow coordinated disclosure and can send the full report and a proof of concept as soon as there is a private channel. I would also like a CVE and credit once it is confirmed.

Thanks,
Mykhailo Kholiev

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。