Is the security reporting channel monitored?
Questions
This is a process question only. I am not discussing any vulnerability details here.
I submitted a report through GitHub’s private security advisory feature on 16 July. I also followed up on 9 August at [email protected], which SECURITY.md lists as an alternate reporting channel. I have not yet received an acknowledgment through either route, and the advisory has not been opened.
SECURITY.md states that reports are normally acknowledged within 48 hours and requests a 90-day remediation window. I have agreed to that 90-day window and communicated its end date in my follow-up.
Could someone confirm whether either reporting route is monitored, or point me to the right contact? I’m happy to coordinate on any appropriate timeline; I’m only seeking an acknowledgment that the report was received.
Source: eigent-ai/eigent