| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
GitHub takes the security of our software products and services seriously, including the open source code repositories managed through our GitHub organizations, such as cli.
If you believe you have found a security vulnerability in GitHub CLI, you can report it to us in one of two ways:
Report it to this repository directly using private vulnerability reporting.
Submit the report through HackerOne to be eligible for a bounty reward.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
A dependency having a CVE does not mean gh has a vulnerability. We use govulncheck to determine whether vulnerable symbols are actually reachable from gh's code. If you are reporting a dependency CVE, please include evidence that the issue is exploitable in gh: a call chain into the affected symbols or a proof of concept. Reports that only list a dependency version and CVE without demonstrating impact will be closed.
Thanks for helping make GitHub safe for everyone.
| Back | FazBrowse Home | New Git URL |