Hi — I have a security report for the workflow server and I could not find a private channel for it.
There is no SECURITY.md in this repository or in the OpenBMB/.github organisation profile, and GitHub's private vulnerability reporting is disabled here, so there is no way for me to send the details without posting them publicly.
Could you either:
- enable Settings → Security → Private vulnerability reporting, and I will file the full report there, or
- reply here (or contact me directly) with a security address you would like me to use?
I have deliberately included no technical detail in this issue. I am not disclosing publicly and I am happy to follow whatever timeline you prefer once a private channel exists.
For context on why I am asking rather than opening a normal issue: the last report of this kind (#638) was filed publicly before a fix existed, and this one is in the same area.
Thanks,
kta1kri
Hi — I have a security report for the workflow server and I could not find a private channel for it.
There is no
SECURITY.mdin this repository or in theOpenBMB/.githuborganisation profile, and GitHub's private vulnerability reporting is disabled here, so there is no way for me to send the details without posting them publicly.Could you either:
I have deliberately included no technical detail in this issue. I am not disclosing publicly and I am happy to follow whatever timeline you prefer once a private channel exists.
For context on why I am asking rather than opening a normal issue: the last report of this kind (#638) was filed publicly before a fix existed, and this one is in the same area.
Thanks,
kta1kri