Security: requesting a private channel to report a critical vulnerability (no details here)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
リポジトリの SECURITY.md と、issue で言及されている GitHub Security Advisories の private-reporting エントリーポイントから始めてください。非公開の脆弱性レポート、proof of concept、提案されたパッチ、回帰テストを共有できるように、非公開チャネルが有効化されるか、非公開のセキュリティ連絡先が提供されれば、issue は完了です。
索引モデルが issue の本文から書いたものです。
説明
Hi maintainers 👋
I've identified what I assess as a critical-severity security vulnerability in BitFun, reproduced against the current main branch.
I'm intentionally withholding all technical details here — no affected file, component, mechanism, or proof-of-concept — because publicly disclosing an unpatched issue would put current users at risk. This follows the project's own SECURITY.md / coordinated-disclosure policy.
I already have a complete report ready to share privately, including:
- Root-cause analysis and the exact location
- A working, self-contained proof-of-concept
- CVSS 3.1 scoring
- A proposed patch (diff) plus a regression test
What I need to proceed: a private channel. Right now the repo's /security/advisories/new link isn't usable by non-maintainers because Private Vulnerability Reporting appears to be disabled. Please do one of:
- Enable Private Vulnerability Reporting — repo Settings → Code security and analysis → Private vulnerability reporting → Enable. I'll then submit the full report through GitHub Security Advisories; or
- Reply with a private security contact (e.g. a security email) I can send the report to.
Once a private channel is open I'll hand over everything immediately, and I'm happy to coordinate a disclosure timeline after you've had a chance to review and patch.
Flagging as high priority given the severity. Thanks for building BitFun! 🙏
- 主要言語
- Rust
- スター
- 2.3k
- フォーク
- 236
- 平均マージ
- 2時間 53分
- マージ済み PR(30日)
- 404
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
GCWing/OpenBitFun のほかの issue
-
難易度 2/5 半日 初心者へのやさしさ 74/100
GCWing/OpenBitFun#3279 ·
メンテナーはふだん 1 日以内に返信
-
[Bug]: 界面写“敏感诊断信息默认关闭”,但后端配置当前实际默认是 true対応中かも @xiechimon が 12 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
GCWing/OpenBitFun#3213 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
GCWing/OpenBitFun#2363 ·
メンテナーはふだん 1 日以内に返信
-
question
難易度 1/5 1時間未満 初心者へのやさしさ 78/100
GCWing/OpenBitFun#2340 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
GCWing/OpenBitFun#3278 ·
メンテナーはふだん 1 日以内に返信
GCWing/OpenBitFun の issue をすべて見る
似ている issue
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
zcashlabs/thus-spoke-zakura#153 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 79/100
topgrade-rs/topgrade#2395 ·
メンテナーはふだん 1 日以内に返信
-
app bug windows-os
難易度 2/5 1〜3時間 初心者へのやさしさ 67/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
matrix-org/matrix-rust-sdk#7217 ·
メンテナーはふだん 1 日以内に返信
-
editor good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
funnyboy-roks/inq#54 ·