Hi maintainers,
I've completed a security audit of mayfly-go and have findings I'd like to share privately. Asking here because:
- The repo doesn't have
SECURITY.md documenting a private channel.
- Private Vulnerability Reporting (GitHub's free private security advisory channel) appears to be disabled — I checked
GET /repos/dromara/mayfly-go/private-vulnerability-reporting and it returns enabled: false.
I'd like to keep vuln details out of public issues so attackers can't get a head-start before a fix lands. Two options:
- Option A (preferred): Enable Private Vulnerability Reporting via Settings → Code security → Private vulnerability reporting → Enable. Free, hides triage discussion from the public, and gives me a structured GHSA channel for the report.
- Option B: Confirm a preferred private channel (email or otherwise) and I'll route there.
Two findings ready to share — both with concrete PoC + suggested patches. Happy to wait at your pace. No disclosure clock.
For context: this is part of a broader coordinated-disclosure campaign that has filed 20 advisories via the GHSA reporter API across 9 maintainer orgs over the past two weeks (1Panel-dev, mudler/LocalAI, donknap/dpanel, nezhahq/nezha, IceWhaleTech/CasaOS-Gateway, henrygd/beszel, amir20/dozzle, crowdsecurity/crowdsec, 1Panel-dev's KubePi). All 20 are in triage state today; none have been published or weaponized.
Thanks!
— Eddie Ran
Hi maintainers,
I've completed a security audit of mayfly-go and have findings I'd like to share privately. Asking here because:
SECURITY.mddocumenting a private channel.GET /repos/dromara/mayfly-go/private-vulnerability-reportingand it returnsenabled: false.I'd like to keep vuln details out of public issues so attackers can't get a head-start before a fix lands. Two options:
Two findings ready to share — both with concrete PoC + suggested patches. Happy to wait at your pace. No disclosure clock.
For context: this is part of a broader coordinated-disclosure campaign that has filed 20 advisories via the GHSA reporter API across 9 maintainer orgs over the past two weeks (1Panel-dev, mudler/LocalAI, donknap/dpanel, nezhahq/nezha, IceWhaleTech/CasaOS-Gateway, henrygd/beszel, amir20/dozzle, crowdsecurity/crowdsec, 1Panel-dev's KubePi). All 20 are in
triagestate today; none have been published or weaponized.Thanks!
— Eddie Ran