Skip to content

[Security] Please enable private vulnerability reporting #4551

Description

@qxyuan853

Search before asking

  • I had searched in the issues and found no similar feature requirement.

Description

Thank you for merging the security policy into this repository! 🎉

I noticed that the "Report a security vulnerability" option currently redirects users to the security policy page rather than providing a private channel to submit vulnerability reports.

Could you please enable the private vulnerability reporting feature on GitHub? This can be done via:

Settings → Code security and analysis → Private vulnerability reporting → Enable

Once enabled, security researchers and users will be able to submit vulnerability reports privately and confidentially through GitHub's built-in mechanism, rather than having to disclose issues publicly through a regular issue.

Thank you for your continued effort in improving the security of this project!

Use case

When a security researcher discovers a vulnerability in this project, they need a private and secure channel to report it without publicly disclosing the details. Enabling GitHub's private vulnerability reporting allows researchers to submit reports confidentially, giving maintainers the opportunity to address the issue before it becomes public knowledge.

Related issues

No response

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Activity

  1. gaoyan1998 commented on Apr 22, 2026

    @gaoyan1998
    Contributor

    @qxyuan853 Thank you for your contribution. It has now been activated.

  2. aiwenmo commented on Apr 22, 2026

    @aiwenmo
    Contributor

    @qxyuan853 Thanks for your feedback. I've just enabled it.

  3. qxyuan853 commented on Apr 23, 2026

    @qxyuan853
    ContributorAuthor

    Thank you! I have reported the vulnerability through the private disclosure channel.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions