Skip to content

[Security] Coordinated disclosure pending — please enable PVR or confirm private channel #128

Description

@eddieran

Hi maintainers,

I've completed a security audit of mayfly-go and have findings I'd like to share privately. Asking here because:

  1. The repo doesn't have SECURITY.md documenting a private channel.
  2. Private Vulnerability Reporting (GitHub's free private security advisory channel) appears to be disabled — I checked GET /repos/dromara/mayfly-go/private-vulnerability-reporting and it returns enabled: false.

I'd like to keep vuln details out of public issues so attackers can't get a head-start before a fix lands. Two options:

  • Option A (preferred): Enable Private Vulnerability Reporting via Settings → Code security → Private vulnerability reporting → Enable. Free, hides triage discussion from the public, and gives me a structured GHSA channel for the report.
  • Option B: Confirm a preferred private channel (email or otherwise) and I'll route there.

Two findings ready to share — both with concrete PoC + suggested patches. Happy to wait at your pace. No disclosure clock.

For context: this is part of a broader coordinated-disclosure campaign that has filed 20 advisories via the GHSA reporter API across 9 maintainer orgs over the past two weeks (1Panel-dev, mudler/LocalAI, donknap/dpanel, nezhahq/nezha, IceWhaleTech/CasaOS-Gateway, henrygd/beszel, amir20/dozzle, crowdsecurity/crowdsec, 1Panel-dev's KubePi). All 20 are in triage state today; none have been published or weaponized.

Thanks!

— Eddie Ran

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions