Skip to content

Private channel for reporting a security issue #781

@Wang-Haimin

Description

@Wang-Haimin

Hello maintainers,

I found a potential security issue affecting a GitHub Actions workflow in this repository.

I do not want to disclose technical details publicly before maintainers have reviewed them. Could you please enable GitHub private vulnerability reporting or provide an alternative private security contact email?

I can provide a detailed report including:

  • affected workflow path;
  • current affected commit;
  • vulnerability mechanism;
  • required attacker permissions and preconditions;
  • security impact assessment;
  • non-destructive validation steps;
  • suggested remediation.

Thank you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions