Skip to content

Security: could you enable a private channel so I can report a workflow issue? / 能否开启私密渠道以便报告一个 workflow 安全问题? #1522

Description

@kobihikri

Hello, and thank you for Kirara AI.

I think I have found a security issue in one of the repository's GitHub Actions workflows, and I would like to report it privately rather than describe it in a public issue — a public description would effectively be a disclosure before you have had a chance to act.

I could not find a private channel for the project: there is no SECURITY.md, and GitHub's private vulnerability reporting does not appear to be enabled. Could you either:

  • enable private vulnerability reporting (Settings → Security → Private vulnerability reporting), or
  • add a SECURITY.md with a contact, or
  • share a security contact (email / other) here,

so I can send the details privately? Once a channel exists I will send the full write-up, which includes the affected file, the exact lines, and a suggested fix. It is a workflow-configuration issue rather than anything in the deployed bot, and I have not run anything against your infrastructure.

Thank you for your time.


你好,感谢你们开发 Kirara AI。

我认为在仓库的某个 GitHub Actions workflow 中发现了一个安全问题,希望私下报告,而不是在公开 issue 中描述——公开描述相当于在你们处理之前就披露了漏洞。

我没有找到私密的报告渠道:仓库没有 SECURITY.md,也似乎没有启用 GitHub 的私密漏洞报告功能。能否请你们:

  • 启用 Private vulnerability reporting(Settings → Security),或
  • 添加带联系方式的 SECURITY.md,或
  • 在此处提供一个安全联系方式(邮箱等)?

有了渠道之后,我会把完整说明(涉及的文件、具体行号和修复建议)私下发给你们。这是一个 workflow 配置问题,与已部署的机器人本身无关,我也没有对你们的基础设施进行任何测试。

谢谢!


Disclosure: I used an AI assistant to help find this and to draft this message; I verified the workflow file myself. / 说明:我借助了 AI 助手来发现问题并起草此消息,workflow 文件由我本人核实。

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions