Skip to content

[Security] Please enable private vulnerability reporting #4551

@qxyuan853

Description

@qxyuan853

Search before asking

  • I had searched in the issues and found no similar feature requirement.

Description

Thank you for merging the security policy into this repository! 🎉

I noticed that the "Report a security vulnerability" option currently redirects users to the security policy page rather than providing a private channel to submit vulnerability reports.

Could you please enable the private vulnerability reporting feature on GitHub? This can be done via:

SettingsCode security and analysisPrivate vulnerability reporting → Enable

Once enabled, security researchers and users will be able to submit vulnerability reports privately and confidentially through GitHub's built-in mechanism, rather than having to disclose issues publicly through a regular issue.

Thank you for your continued effort in improving the security of this project!

Use case

When a security researcher discovers a vulnerability in this project, they need a private and secure channel to report it without publicly disclosing the details. Enabling GitHub's private vulnerability reporting allows researchers to submit reports confidentially, giving maintainers the opportunity to address the issue before it becomes public knowledge.

Related issues

No response

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions