There should be a way to securely report security vulnerabilities. It should be on the README or a link to a generic telehash one.
But it should be clear that github is not the place to do this. Ideally there should be a GPG key to send this to but some companies have a security reporting template.
There should be a way to securely report security vulnerabilities. It should be on the README or a link to a generic telehash one.
But it should be clear that github is not the place to do this. Ideally there should be a GPG key to send this to but some companies have a security reporting template.