Skip to content

Security: requesting a private disclosure channel (no details included) #667

Description

@kta1kri

Hi — I have a security report for the workflow server and I could not find a private channel for it.

There is no SECURITY.md in this repository or in the OpenBMB/.github organisation profile, and GitHub's private vulnerability reporting is disabled here, so there is no way for me to send the details without posting them publicly.

Could you either:

  1. enable Settings → Security → Private vulnerability reporting, and I will file the full report there, or
  2. reply here (or contact me directly) with a security address you would like me to use?

I have deliberately included no technical detail in this issue. I am not disclosing publicly and I am happy to follow whatever timeline you prefer once a private channel exists.

For context on why I am asking rather than opening a normal issue: the last report of this kind (#638) was filed publicly before a fix existed, and this one is in the same area.

Thanks,
kta1kri

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions