Security contact needed — no SECURITY.md or private reporting channel

Open Beginner friendly
#930 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
75/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
github

Research direction

Start by checking whether the repository root contains SECURITY.md, then review GitHub Settings → Security for Private Vulnerability Reporting. Done means a private reporting channel is available and the repository provides a SECURITY.md or private security contact explaining how to report vulnerabilities.

Written by the indexing model from the issue text.

Description

Hi maintainers, I'd like to report a security issue in fastcore privately rather than in a public issue, but this repo has no SECURITY.md and GitHub Private Vulnerability Reporting (/security/advisories/new) is not enabled. Could you enable Private Vulnerability Reporting (Settings → Security), add a SECURITY.md, or point me to a private security contact? I'll send full details there. Thanks!

— Mohammad Adnan (CyStack red team), GitHub @mohammedix88

Dominant language
Jupyter Notebook
Stars
1.1k
Forks
295
Avg merge
1d 6h
Merged PRs (30d)
7

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AnswerDotAI/fastcore

All issues in AnswerDotAI/fastcore

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.