Please do not open a public issue for a security problem.
Use GitHub's private vulnerability reporting instead: go to the repository's Security tab and choose Report a vulnerability. That opens a private thread visible only to me, and it works without either of us publishing an email address.
If that is unavailable for some reason, reach me through LinkedIn.
| First reply | Within 7 days |
| Assessment | Within 14 days |
| Fix or a stated reason not to | Within 30 days for anything exploitable |
These are personal projects maintained in evenings and weekends, so I would rather promise a timeline I can keep than a fast one I cannot.
These are libraries and static sites. There is no server holding your data and no account to compromise, so the realistic risk surface is narrower than for a hosted product. Things genuinely worth reporting:
- Input that causes a parser to hang, crash, or consume unbounded memory
- A dependency with a known advisory that one of these repos pulls in
- Anything in the published examples that would be unsafe if copied into production, which for the integration repos is the one that would bother me most
- Credentials or personal data committed by accident
- Missing hardening headers on a GitHub Pages site I do not control the serving of
- Results from an automated scanner with no demonstrated impact
- Anything requiring an attacker to already control the victim's machine
Tell me how you want to be credited and I will do it. If you would rather stay anonymous, that is fine too.
Bitte kein öffentliches Issue für ein Sicherheitsproblem.
Nutze stattdessen GitHubs private Meldefunktion: im Repository auf den Reiter Security und dort Report a vulnerability. Das öffnet einen privaten Thread, den nur ich sehe, und funktioniert, ohne dass einer von uns eine E-Mail-Adresse veröffentlicht.
Falls das nicht geht, erreichst du mich über LinkedIn.
| Erste Rückmeldung | Innerhalb von 7 Tagen |
| Einschätzung | Innerhalb von 14 Tagen |
| Fix oder eine begründete Ablehnung | Innerhalb von 30 Tagen, sofern ausnutzbar |
Das sind private Projekte, gepflegt an Abenden und Wochenenden. Mir ist eine Frist lieber, die ich halte, als eine schnelle, die ich reiße.
Es handelt sich um Bibliotheken und statische Seiten. Es gibt keinen Server mit deinen Daten und keinen Account zum Übernehmen, die realistische Angriffsfläche ist also kleiner als bei einem gehosteten Produkt. Wirklich meldenswert:
- Eingaben, bei denen ein Parser hängt, abstürzt oder unbegrenzt Speicher frisst
- Eine Abhängigkeit mit bekannter Advisory, die eines dieser Repos hereinzieht
- Alles in den veröffentlichten Beispielen, das unsicher wäre, wenn man es in Produktion kopiert. Bei den Integrations-Repos wäre mir genau das am unangenehmsten
- Versehentlich committete Zugangsdaten oder personenbezogene Daten
- Fehlende Security-Header auf einer GitHub-Pages-Seite, deren Auslieferung ich nicht steuere
- Scanner-Ergebnisse ohne belegte Auswirkung
- Alles, wofür ein Angreifer bereits den Rechner des Opfers kontrollieren muss
Sag mir, wie du genannt werden möchtest, dann mache ich das. Anonym ist genauso in Ordnung.