Skip to content

[Security] Request for a private vulnerability reporting channel #160

Description

@superbigcup325

Per SECURITY.md ("GitHub private vulnerability reporting is not currently
enabled... open an issue without vulnerability details asking maintainers for
a private channel"), this issue contains no vulnerability details.

I have two verified security findings against mcode 0.4.12 (Linux, Node 26):

  1. a terminal-output handling issue in the TUI render path (this one is the
    more serious of the two)
  2. an issue in how the agent's file tools interact with mcode's own
    credential storage

Both have minimal reproductions and redacted evidence ready, neither involves
real credentials, and neither is currently discussed anywhere public.

Since the repo's private vulnerability reporting is not enabled and no
security email is listed, could you either enable Security → Advisories →
Report a vulnerability, or point me at an alternative private channel? Once
one exists I will submit the full write-ups there.

cc @hetaoBackend (release coordinator per docs/maintainers.md)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions