🐛 [BUG] - Private security advisories filed in June have received no maintainer response
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 169
- Forks
- 67
- PR merge metrics
- No merged PRs in 30d
Description
Description
Three GitHub Private Vulnerability Reports were filed on this
repository on June 7, 2026. All three remain in Triage with zero
maintainer comments after 103 days.
An email was also sent on July 8 to the security contact listed in
the README (Justin.R.Morris@nasa.gov with
gsfc-softwarerequest@mail.nasa.gov copied), without a reply.
This issue is not about the technical content of those reports,
which stays in the private channel. It is only to ask whether the
private advisory queue is being monitored, since public issues
here appear to get attention while the private ones do not.
Could a maintainer confirm the right channel for security
reports?
Branch Name
N/A
Reproduction steps
N/A - this issue is about the disclosure process, not a technical
defect.
Screenshots

Logs
OS
Linux
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read the security contact listed in README and review the issue description, which keeps the advisory details private. This issue is done when a maintainer confirms whether the private advisory queue is monitored and identifies the correct channel for security reports.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100