Private channel for reporting a security issue

#781 · open · 2 comments

View on GitHub ↗

Wang-Haimin

Hello maintainers, I found a potential security issue affecting a GitHub Actions workflow in this repository. I do not want to disclose technical details publicly before maintainers have reviewed them. Could you please enable GitHub private vulnerability reporting or provide an alternative private security contact email? I can provide a detailed report including: - affected workflow path; - current affected commit; - vulnerability mechanism; - required attacker permissions and preconditions; - security impact assessment; - non-destructive validation steps; - suggested remediation. Thank you.

Comments

ahmad-moussawi

Hey @Wang-Haimin I've enabled the "private vulnerability reporting" settings

Wang-Haimin

Hi, Thank you for enabling GitHub private vulnerability reporting. I will submit the full technical report through the private GitHub Security advisory channel. Thanks again.