tidbcloud / tidbcloud/tidbcloud-uikit

Security inquiry — please enable Private Vulnerability Reporting

Open
#643 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
7
Forks
1
Avg merge
2h 38m
Merged PRs (30d)
9

Description

Hi the TiDB Cloud / PingCAP team,

I'm an independent security researcher (GitHub: @cyberkareem) with a private vulnerability report ready for this repository — live-validated end-to-end against the current default branch.

Your security policy / SECURITY.md points to GitHub Security Advisories (GHSA) as the disclosure channel, but the Private Vulnerability Reporting (PVR) feature is not currently enabled on this repo. The GHSA private-report API at POST /repos/tidbcloud/tidbcloud-uikit/security-advisories/reports returns HTTP 403 "Repository does not have private vulnerability reporting enabled", so I cannot file the draft advisory through the proper channel.

To enable PVR (~30 seconds, admin/maintainer only):

  1. Open: https://github.com/tidbcloud/tidbcloud-uikit/settings/security_analysis
  2. Scroll to Private vulnerability reporting
  3. Click Enable

Once enabled, I'll submit the draft advisory within the hour. Only you (and collaborators with appropriate repo access) will see it — there is no public visibility until you publish or 90 days elapse, whichever you prefer.

To help triage priority:

  • Severity (self-assessed): Critical
  • Status: live-validated end-to-end
  • No public disclosure to date — this is the only outreach
  • Disclosure preference: 90-day coordinated disclosure (GHSA default), flexible on your timeline

Happy to share any additional context that helps you triage. Please reply here or flip the PVR toggle and I'll file the report immediately. I'm not naming the bug class publicly to preserve responsible disclosure norms; that detail goes in the private advisory once PVR is enabled.

Thanks for shipping this project publicly with a security policy.

— Abdullah Kareem ("cyberkareem")
GitHub: https://github.com/CyberKareem
Web: https://linktr.ee/cyberkareem

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with SECURITY.md and the repository's Security analysis settings at /settings/security_analysis. Enable Private vulnerability reporting, then confirm the researcher can submit the draft advisory through the GHSA private-report endpoint.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
1/5
Estimated time
Under an hour
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.