Hello maintainers, I would like to submit a security-related finding from a static code review privately, following SECURITY.md.
The designated private reporting URL, https://github.com/cnodejs/cnode-next/security/advisories/new, returns GitHub's 404 (Page not found) while I am signed in. I also could not find a reporting button on the repository's Security page.
I am opening this minimal public issue as the fallback described in the security policy, solely to request a private contact channel. Could you enable GitHub Private Vulnerability Reporting or provide another private reporting channel approved by the maintainers?
To avoid disclosing details before a fix, I am not including impact, source locations, or reproduction details here. I will share the full report and suggested fix privately. Would you also welcome a subsequent PR with a minimal fix and regression tests, after we agree on the scope through the private channel?
Thank you.
Reactions are currently unavailable
Hello maintainers, I would like to submit a security-related finding from a static code review privately, following SECURITY.md.
The designated private reporting URL, https://github.com/cnodejs/cnode-next/security/advisories/new, returns GitHub's 404 (Page not found) while I am signed in. I also could not find a reporting button on the repository's Security page.
I am opening this minimal public issue as the fallback described in the security policy, solely to request a private contact channel. Could you enable GitHub Private Vulnerability Reporting or provide another private reporting channel approved by the maintainers?
To avoid disclosing details before a fix, I am not including impact, source locations, or reproduction details here. I will share the full report and suggested fix privately. Would you also welcome a subsequent PR with a minimal fix and regression tests, after we agree on the scope through the private channel?
Thank you.